https://seclists.org/oss-sec/2026/q3/504: libmspack: heap buffer overflow in make_decode_table() (Huffman decode table construction) -- CVE quested
Affected Software
Frequently Asked Questions
Which deployments are potentially exposed?
Deployments using libmspack to process CAB, CHM, LIT, HLP, KWAJ, or SZDD content may be exposed. The report specifically notes use by cabextract and vendored use by ClamAV as libclammspack, among others.
What does an attacker need to exploit this issue?
An attacker needs to supply a hand-crafted input file that reaches the affected Huffman decode-table construction through a real library API. The report states that the triggering input uses a format-legal code-length distribution.
Would callers receive an error if exploitation occurs?
No. The affected function can write beyond the caller-allocated decode table while returning success, so the caller has no indication that the overflow occurred.
Is a CVE or fix available?
No CVE had been assigned at the time of the report. The issue was reported directly to the maintainer on 2026-08-16, and further trigger and affected-call-site details were being withheld pending coordinated disclosure.