haitam lazaar / lazaarsec
← Back to CVE Registry
CVE-2026-917528.7high[patched]

Stack Overflow via Excessive Stack Allocation in OLE2 Plugin

TARGET ECOSYSTEM / VENDORGNU Project
AFFECTED PRODUCTlibextractor (< 1.15)
CWE CLASSIFICATIONCWE-789 / CWE-121: Stack-based Buffer Overflow
PUBLISHED DATE2026-09-14
ADVISORY / CNARepository / PoC ↗

Summary

A stack-based buffer overflow in GNU libextractor’s OLE2 plugin allows remote denial of service (crash) and code execution when processing a crafted .doc file. The vulnerability is located in process_star_office() (ole2_extractor.c:349), which allocates a Variable Length Array (VLA) of up to 4MB on the stack based on attacker-controlled file data.

Impact & Exploitation

  • Primary Impact: Remote Denial of Service — crashes any application processing the malicious file.
  • Secondary Impact: Remote Code Execution via adjacent-thread-stack bypass of -fstack-clash-protection.
  • CNA: VulnCheck
  • Fixed In: GNU libextractor v1.15

Research Repository

A full lab environment, standalone PoCs, and bypass documentation are hosted in Haitam-lazaar/libextractor-ole2-rce.