Notice USN-8838-1, published on September 28, 2026 in the Ubuntu Security feed, describes three vulnerabilities in catdoc, a tool for processing documents and spreadsheets. The supplied text is an automatic translation; consult the original Ubuntu notice to confirm the details.
The flaws are identified as CVE-2024-48877, CVE-2024-52035, and CVE-2024-54028. The first two involve integer overflows while processing, respectively, shared string tables in malformed spreadsheets and file allocation tables in malformed documents. The third results from incorrect validation of sector sizes, causing an integer underflow.
According to the notice, an attacker could exploit each issue to make catdoc fail or execute arbitrary code while it processes malformed files. If your organization uses the tool, check the original notice and advisories applicable to your installed version; follow official update guidance and avoid processing untrusted files until you have assessed the exposure.
To consult and verify the source, search for identifier USN-8838-1 in the Ubuntu Security feed and check the cited CVE identifiers as well. If you use AI to study the notice or prepare internal procedures, share only what is necessary and remove personal data, credentials, and confidential information.