Source: r-cran-readxl X-Debbugs-CC: [email protected] Severity: important Tags: security
Hi, The following vulnerabilities were published for libxls, which r-cran-readxl embeds: CVE-2026-79591[0]: | A heap-buffer-overflow and use-after-free vulnerability exists in | the xls_getCSS() function of libxls 1.6.3 due to insufficient | validation of a file-controlled font index. https://github.com/libxls/libxls/issues/161 https://github.com/libxls/libxls/pull/164/changes/902c8f9b13710c3a13b6232fb86626c5c729402c CVE-2026-79592[1]: | An out-of-bounds read vulnerability exists in the xls_dumpSummary() | function of libxls 1.6.3 due to insufficient validation of file- | controlled OLE summary offsets. https://github.com/libxls/libxls/issues/162 https://github.com/libxls/libxls/pull/165/changes/6eed8bc1d51d6649faebab0184b21ab8768d8fa6 If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-79591 https://www.cve.org/CVERecord?id=CVE-2026-79591 [1] https://security-tracker.debian.org/tracker/CVE-2026-79592 https://www.cve.org/CVERecord?id=CVE-2026-79592 Please adjust the affected versions in the BTS as needed.

