https://seclists.org/oss-sec/2026/q3/813: CVE-2026-91752: GNU libextractor < 1.15 Stack Overflow via OLE2

Published Sep 16, 2026
·
Updated

Affected Software

1 affected component
GNU Libextractor<1.15

Frequently Asked Questions

1

Which deployments face code-execution risk rather than only a crash?

The stated code-execution condition is a multi-threaded application using EXTRACTOR_OPTION_IN_PROCESS. In other described cases, a malicious StarOffice document can cause a stack overflow and denial of service when metadata is extracted.

2

What must an attacker provide to trigger the issue?

An attacker must supply a crafted malicious StarOffice document containing attacker-controlled OLE2 stream data. The vulnerable OLE2 plugin processes this data while extracting metadata.

3

Are default installations affected?

The available information identifies affected versions as libextractor versions from 0 up to, but not including, 1.15. It does not state whether the OLE2 plugin or in-process extraction option is enabled by default.

4

What is the available remediation?

Upgrade GNU libextractor to version 1.15, which is identified as containing the fix. The supplied information does not describe a workaround for systems that cannot be upgraded immediately.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203