As cited
Copy frozen at (site build).
vulnerabilities
CVE-2026-91752: GNU libextractor < 1.15 Stack Overflow via OLE2
GNU libextractor before version 1.15 contains a stack-based buffer overflow in the OLE2 plugin, specifically in the process_star_office function that allocates stack memory based on attacker-controlled data. CVE-2026-91752 affects the library's handling of malicious OLE2 stream input.
Why it matters: Organizations and developers using GNU libextractor versions prior to 1.15 to process potentially untrusted OLE2 files face remote code execution risk and should upgrade immediately.
- Source published
- First seen by Cybersecurity Tracker