CVE-2026-91752
GNU libextractor before 1.15 contains a stack-based buffer overflow vulnerability in the process_star_office function that sizes a variable-length stack array from attacker-controlled OLE2 stream data. Attackers can craft malicious StarOffice documents that allocate up to 4 MB on the stack, causing stack overflow and crashing any application extracting metadata from the document.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.7
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.39%
- CWE
- CWE-789
- Published
- 2026-09-15
- Last modified
- 2026-09-17
Affected products
- GNU libextractor
Weakness type
Related vulnerabilities
- CVE-2026-25579 — Navidrome affected by Denial of Service and disk exhaustion via oversized `size` parameter in `/rest/getCoverArt` and `/share/img/<token>` endpoints
- CVE-2026-5740 — Unauthenticated WebSocket binary frame causes denial of service in Mattermost Server
- CVE-2026-28253 — Memory Allocation with Excessive Size Value vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge
- CVE-2025-54801 — Fiber Susceptible to Crash via `BodyParser` Due to Unvalidated Large Slice Index in Decoder
- CVE-2026-49975 — Apache HTTP Server: mod_http2 denial of service
- CVE-2026-22803 — SvelteKit has a memory amplification DoS in Remote Functions binary form deserializer
- CVE-2026-22026 — CryptoLib Unbounded Memory Allocation in KMC HTTP Response Handler Allows Resource Exhaustion
- CVE-2026-82435 — Apache Storm Worker: Unauthenticated Remote Memory Exhaustion in the Worker Messaging Decoder