CVE-2026-91752: GNU libextractor before 1.15 Stack Overflow via OLE2

Published Sep 15, 2026
·
Updated

GNU libextractor before 1.15 contains a stack-based buffer overflow vulnerability in the processstaroffice function that sizes a variable-length stack array from attacker-controlled OLE2 stream data. Attackers can craft malicious StarOffice documents that allocate up to 4 MB on the stack, causing stack overflow and crashing any application extracting metadata from the document.

Affected Software

1 affected component
GNU Libextractor<1.15

Event History

Sep 15, 2026
CVE Published
via MITRE·12:35 AM
Data Sourced
via MITRE·12:35 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed?

Any application that uses GNU libextractor before 1.15 to extract metadata from untrusted StarOffice documents is exposed. The vulnerable code processes attacker-controlled OLE2 stream data.

2

What must an attacker do to trigger the issue?

An attacker must provide a crafted StarOffice document containing malicious OLE2 stream data. No privileges or user interaction are indicated by the supplied CVSS vector.

3

What is the expected impact?

The crafted stream can cause libextractor to allocate up to 4 MB on the stack, leading to a stack overflow and crash of the application performing metadata extraction. The provided impact information indicates availability impact only.

4

How can I determine whether an installation is affected?

Check the GNU libextractor version used by the metadata-extracting application. Versions before 1.15 are affected when they process StarOffice OLE2 documents.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203