Linuxsecurity
Fedora 44 and 43 libxls Patches Address Critical Information Disclosure Vulnerabilities
Article Content
On August 15, 2026, Fedora released vital updates for libxls, a C library for reading Excel files, addressing two critical vulnerabilities (CVE-2026-26824 and CVE-2026-26825) that could lead to information disclosure via crafted XLS file processing and uninitialized memory use. These vulnerabilities affect Fedora 43 and 44 systems. The patches were backported by Elliott Sales de Andrade and can be installed using the 'dnf' update program. The vulnerabilities were published on June 3, 2026, and are now patched, but users are urged to update their systems promptly to mitigate potential risks. The updates are crucial for maintaining the security of systems utilizing the libxls library, especially in environments handling sensitive data.
Key Points: • Two critical vulnerabilities in libxls patched for Fedora 43 and 44. • CVE-2026-26824 and CVE-2026-26825 can lead to information disclosure. • Users are advised to update their systems using the 'dnf' command.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.