On 11 September 2026 at 18:56, Moritz Mühlenhoff wrote:
| Source: r-cran-readxl
| X-Debbugs-CC: [email protected]
| Severity: important
| Tags: security
| 
| Hi,
| 
| The following vulnerabilities were published for libxls, which
| r-cran-readxl embeds:
| 
| 
| CVE-2026-79591[0]:
| | A heap-buffer-overflow and use-after-free vulnerability exists in
| | the xls_getCSS() function of libxls 1.6.3 due to insufficient
| | validation of a file-controlled font index.
| 
| https://github.com/libxls/libxls/issues/161
| 
https://github.com/libxls/libxls/pull/164/changes/902c8f9b13710c3a13b6232fb86626c5c729402c
|  
| 
| CVE-2026-79592[1]:
| | An out-of-bounds read vulnerability exists in the xls_dumpSummary()
| | function of libxls 1.6.3 due to insufficient validation of file-
| | controlled OLE summary offsets.
| 
| https://github.com/libxls/libxls/issues/162
| 
https://github.com/libxls/libxls/pull/165/changes/6eed8bc1d51d6649faebab0184b21ab8768d8fa6

Thanks. This is on top of #1139808 which I forwarded upstream [1] -- for no
actual follow-up yet I can see. I added these there.

Dirk

[1] https://github.com/tidyverse/readxl/issues/795
| 
| 
| If you fix the vulnerabilities please also make sure to include the
| CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.
| 
| For further information see:
| 
| [0] https://security-tracker.debian.org/tracker/CVE-2026-79591
|     https://www.cve.org/CVERecord?id=CVE-2026-79591
| [1] https://security-tracker.debian.org/tracker/CVE-2026-79592
|     https://www.cve.org/CVERecord?id=CVE-2026-79592
| 
| Please adjust the affected versions in the BTS as needed.

-- 
dirk.eddelbuettel.com | @eddelbuettel | [email protected]

Reply via email to