CVE-2026-107215: Excelize: extractPart allocates attacker-controlled, unbounded and negative-sized buffers from CFB directory entries: remote panic / OOM DoS
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.3.1 to 2.11.0, extractPart allocates a byte slice directly from an attacker-controlled CFB directory-entry size before validating the sector chain or size domain. extractPart trusts the CFB directory entry streamSize for EncryptionInfo and EncryptedPackage allocations before validating the stream. When a crafted OLE compound file declares a negative or extremely large EncryptionInfo or EncryptedPackage stream size, the declared size reaches make with a negative length or forces a multi-gigabyte allocation, allowing an attacker to panic or exhaust process memory. No fixed version is available as of this review.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this denial-of-service issue?
Applications using Excelize versions 2.3.1 through 2.11.0 to process attacker-controlled or otherwise untrusted OLE compound Excel files are exposed. The affected parsing path handles EncryptionInfo and EncryptedPackage streams.
What does an attacker need to exploit it?
An attacker needs to provide a crafted OLE compound file with a negative or extremely large directory-entry streamSize for EncryptionInfo or EncryptedPackage. Exploitation does not require authentication or user interaction according to the supplied vector.
What happens when a malicious file is processed?
The library can pass the declared stream size directly to a byte-slice allocation before validating the stream. A negative size can panic the process, while an extremely large size can consume multi-gigabyte memory and cause an out-of-memory denial of service.
Is a fixed version available?
No fixed version was available as of this review. The provided references include an upstream pull request and commit related to the issue.