Stack-based buffer overflow in Libextractor - CVE-2026-91752
Published: September 21, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a stack-based buffer overflow in the process_star_office function of the OLE2 plugin when processing attacker-controlled OLE2 stream data. A remote attacker can provide a crafted StarOffice document to execute arbitrary code.
This condition requires a multi-threaded context using EXTRACTOR_OPTION_IN_PROCESS.