CYBERSECURITYTRACKER
TRACKING6,877 stories in this site build1,441 vulnerability news stories in this site build
Permanent story citation

CVE-2026-91752: GNU libextractor < 1.15 Stack Overflow via OLE2

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 7576

As cited

Copy frozen at (site build).

vulnerabilities

CVE-2026-91752: GNU libextractor < 1.15 Stack Overflow via OLE2

GNU libextractor before version 1.15 contains a stack-based buffer overflow in the OLE2 plugin, specifically in the process_star_office function that allocates stack memory based on attacker-controlled data. CVE-2026-91752 affects the library's handling of malicious OLE2 stream input.

Why it matters: Organizations and developers using GNU libextractor versions prior to 1.15 to process potentially untrusted OLE2 files face remote code execution risk and should upgrade immediately.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary