{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/libextractor--1.15/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:gnu:libextractor:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-91752"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["libextractor (\u003c 1.15)"],"_cs_severities":["low"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["GNU"],"content_html":"\u003cp\u003eGNU libextractor, a library used for extracting metadata from various file types, contains a stack-based buffer overflow vulnerability identified as CVE-2026-91752. The flaw resides within the process_star_office function, which handles StarOffice document formats. When the library parses an OLE2 stream within a crafted StarOffice document, it allocates memory on the stack based on attacker-supplied metadata headers. An attacker can craft a document requesting up to 4 MB of stack space, which exceeds typical stack limits and leads to a memory corruption event. This vulnerability primarily results in a denial-of-service, crashing any application or service that utilizes libextractor to process untrusted file uploads or metadata extraction tasks. Defenders should prioritize updating libextractor to version 1.15 or later to mitigate the risk of arbitrary code execution or service instability.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability poses a high risk to software ecosystems that utilize libextractor for automated file analysis, archival, or indexing. If successfully triggered, the overflow causes an immediate application crash, leading to service disruption. Systems that ingest user-provided documents are at the highest risk, as the exploitation vector requires nothing more than the library processing a malicious file.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eUpdate all instances of GNU libextractor to version 1.15 or later. Ensure that any software packages, dependencies, or local builds of the library are rebuilt and redeployed using the patched source code.\u003c/p\u003e\n","date_modified":"2026-09-15T01:38:15Z","date_published":"2026-09-15T01:38:15Z","id":"https://feed.craftedsignal.io/briefs/2026-09-libextractor-overflow/","summary":"GNU libextractor versions prior to 1.15 contain a stack-based buffer overflow in the process_star_office function that can be triggered by malicious OLE2 stream data to cause application crashes.","title":"Stack-Based Buffer Overflow in GNU libextractor","url":"https://feed.craftedsignal.io/briefs/2026-09-libextractor-overflow/"}],"language":"en","title":"CraftedSignal Threat Feed - Libextractor (\u003c 1.15)","version":"https://jsonfeed.org/version/1.1"}