A use-of-uninitialized memory vulnerability exists in libxls 1.6.3 when parsing malformed XLS files. The issue is reachable via xls_parseWorkBook() and is triggered by uninitialized heap memory originating from the OLE layer (ole2_read). The flaw is detectable with MemorySanitizer (MSAN) and can lead to undefined behavior, incorrect parsing logic, or potential information disclosure.

Project Subscriptions

Vendors Products
Libxls Project Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 05 Jun 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Libxls
Libxls libxls
Vendors & Products Libxls
Libxls libxls

Thu, 04 Jun 2026 22:45:00 +0000

Type Values Removed Values Added
Title Use‑of‑Uninitialized Memory in libxls 1.6.3 During XLS Parsing

Thu, 04 Jun 2026 20:15:00 +0000

Type Values Removed Values Added
Title Uninitialized Memory Use in libxls 1.6.3 Leads to Undefined Behavior and Possible Information Disclosure
Weaknesses CWE-758

Thu, 04 Jun 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Libxls Project
Libxls Project libxls
Weaknesses CWE-908
CPEs cpe:2.3:a:libxls_project:libxls:1.6.3:*:*:*:*:*:*:*
Vendors & Products Libxls Project
Libxls Project libxls
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Wed, 03 Jun 2026 21:45:00 +0000

Type Values Removed Values Added
Title Uninitialized Memory Use in libxls 1.6.3 Leads to Undefined Behavior and Possible Information Disclosure
Weaknesses CWE-758

Wed, 03 Jun 2026 20:15:00 +0000

Type Values Removed Values Added
Description A use-of-uninitialized memory vulnerability exists in libxls 1.6.3 when parsing malformed XLS files. The issue is reachable via xls_parseWorkBook() and is triggered by uninitialized heap memory originating from the OLE layer (ole2_read). The flaw is detectable with MemorySanitizer (MSAN) and can lead to undefined behavior, incorrect parsing logic, or potential information disclosure.
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-06-03T20:01:10.984Z

Reserved: 2026-02-16T00:00:00.000Z

Link: CVE-2026-26825

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-06-03T20:16:18.797

Modified: 2026-06-04T18:41:23.580

Link: CVE-2026-26825

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-05T10:12:14Z

Weaknesses