PatchSiren

libxls CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH libxls CVE published 2026-09-10

CVE-2026-79592

CVE-2026-79592 is a high-severity vulnerability in libxls 1.6.3, allowing for out-of-bounds reads due to insufficient validation of OLE summary offsets. Defenders should assess exposure, prioritize remediation, and verify affected versions. The vulnerability exists in the xls_dumpSummary() function, which fails to properly validate file-controlled OLE summary offsets, potentially allowing attackers to rea [truncated]