Deployments using libmspack to process CAB, CHM, LIT, HLP, KWAJ, or SZDD content may be exposed. The report specifically notes use by cabextract and vendored use by ClamAV as libclammspack, among others.
An attacker needs to supply a hand-crafted input file that reaches the affected Huffman decode-table construction through a real library API. The report states that the triggering input uses a format-legal code-length distribution.
No. The affected function can write beyond the caller-allocated decode table while returning success, so the caller has no indication that the overflow occurred.
No CVE had been assigned at the time of the report. The issue was reported directly to the maintainer on 2026-08-16, and further trigger and affected-call-site details were being withheld pending coordinated disclosure.