Source: r-cran-readxl
X-Debbugs-CC: [email protected]
Severity: important
Tags: security

Hi,

The following vulnerabilities were published for libxls, which
r-cran-readxl embeds:


CVE-2026-79591[0]:
| A heap-buffer-overflow and use-after-free vulnerability exists in
| the xls_getCSS() function of libxls 1.6.3 due to insufficient
| validation of a file-controlled font index.

https://github.com/libxls/libxls/issues/161
https://github.com/libxls/libxls/pull/164/changes/902c8f9b13710c3a13b6232fb86626c5c729402c
 

CVE-2026-79592[1]:
| An out-of-bounds read vulnerability exists in the xls_dumpSummary()
| function of libxls 1.6.3 due to insufficient validation of file-
| controlled OLE summary offsets.

https://github.com/libxls/libxls/issues/162
https://github.com/libxls/libxls/pull/165/changes/6eed8bc1d51d6649faebab0184b21ab8768d8fa6


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-79591
    https://www.cve.org/CVERecord?id=CVE-2026-79591
[1] https://security-tracker.debian.org/tracker/CVE-2026-79592
    https://www.cve.org/CVERecord?id=CVE-2026-79592

Please adjust the affected versions in the BTS as needed.

Reply via email to