← Back to CVE Registry
CVE-2026-917528.7high[patched]
Stack Overflow via Excessive Stack Allocation in OLE2 Plugin
TARGET ECOSYSTEM / VENDORGNU Project
AFFECTED PRODUCTlibextractor (< 1.15)
CWE CLASSIFICATIONCWE-789 / CWE-121: Stack-based Buffer Overflow
PUBLISHED DATE2026-09-14
ADVISORY / CNARepository / PoC ↗
Summary
A stack-based buffer overflow in GNU libextractor’s OLE2 plugin allows remote denial of service (crash) and code execution when processing a crafted .doc file. The vulnerability is located in process_star_office() (ole2_extractor.c:349), which allocates a Variable Length Array (VLA) of up to 4MB on the stack based on attacker-controlled file data.
Impact & Exploitation
- Primary Impact: Remote Denial of Service — crashes any application processing the malicious file.
- Secondary Impact: Remote Code Execution via adjacent-thread-stack bypass of
-fstack-clash-protection. - CNA: VulnCheck
- Fixed In: GNU libextractor v1.15
Research Repository
A full lab environment, standalone PoCs, and bypass documentation are hosted in Haitam-lazaar/libextractor-ole2-rce.