Cyber Resilience
← All news
Confirmed

GNU security advisory (AV26-923)

Our takeCCCS advisory AV26-923 flags a stack overflow in GNU libextractor prior to 1.15. Update to v1.15 or later if you run it yourself.
Sources (1)
What this means for you — Security leader:Update libextractor to v1.15 or later if you run it in production or development environments.
What this means for you — Lean IT orgs:If your systems use the GNU libextractor library (often pulled in by media or file-analysis tools), update it to version 1.15 or newer.
What this means for you — MSP:Check client environments for any use of GNU libextractor prior to v1.15 and update to 1.15+; it is typically a transitive dependency in media-handling stacks.
What this means for you — Researcher:GNU libextractor before v1.15 contains a stack overflow (CVE-2026-91752); see the CCCS advisory for details.