On 11 September 2026 at 18:56, Moritz Mühlenhoff wrote: | Source: r-cran-readxl | X-Debbugs-CC: [email protected] | Severity: important | Tags: security | | Hi, | | The following vulnerabilities were published for libxls, which | r-cran-readxl embeds: | | | CVE-2026-79591[0]: | | A heap-buffer-overflow and use-after-free vulnerability exists in | | the xls_getCSS() function of libxls 1.6.3 due to insufficient | | validation of a file-controlled font index. | | https://github.com/libxls/libxls/issues/161 | https://github.com/libxls/libxls/pull/164/changes/902c8f9b13710c3a13b6232fb86626c5c729402c | | | CVE-2026-79592[1]: | | An out-of-bounds read vulnerability exists in the xls_dumpSummary() | | function of libxls 1.6.3 due to insufficient validation of file- | | controlled OLE summary offsets. | | https://github.com/libxls/libxls/issues/162 | https://github.com/libxls/libxls/pull/165/changes/6eed8bc1d51d6649faebab0184b21ab8768d8fa6
Thanks. This is on top of #1139808 which I forwarded upstream [1] -- for no actual follow-up yet I can see. I added these there. Dirk [1] https://github.com/tidyverse/readxl/issues/795 | | | If you fix the vulnerabilities please also make sure to include the | CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. | | For further information see: | | [0] https://security-tracker.debian.org/tracker/CVE-2026-79591 | https://www.cve.org/CVERecord?id=CVE-2026-79591 | [1] https://security-tracker.debian.org/tracker/CVE-2026-79592 | https://www.cve.org/CVERecord?id=CVE-2026-79592 | | Please adjust the affected versions in the BTS as needed. -- dirk.eddelbuettel.com | @eddelbuettel | [email protected]

