Heap-based buffer overflow in Calibre - #VU146755
Published: September 2, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to a heap-based buffer overflow in cpalmdoc_compress() when processing crafted book content during document conversion. A remote user can supply a specially crafted document or trigger conversion of a crafted book to cause a denial of service.
PalmDoc compression is the default for MOBI and AZW3 output and unconditional for PDB. A write-authenticated content server conversion path is also affected.