Skip to content
Rota Nacional

Guides ·

USN-8838-1: catdoc flaws may allow code execution

A security notice published on September 28, 2026 reports three integer overflow or underflow flaws in catdoc. Malformed files could cause the program to fail or execute arbitrary code.

Notice USN-8838-1, published on September 28, 2026 in the Ubuntu Security feed, describes three vulnerabilities in catdoc, a tool for processing documents and spreadsheets. The supplied text is an automatic translation; consult the original Ubuntu notice to confirm the details.

The flaws are identified as CVE-2024-48877, CVE-2024-52035, and CVE-2024-54028. The first two involve integer overflows while processing, respectively, shared string tables in malformed spreadsheets and file allocation tables in malformed documents. The third results from incorrect validation of sector sizes, causing an integer underflow.

According to the notice, an attacker could exploit each issue to make catdoc fail or execute arbitrary code while it processes malformed files. If your organization uses the tool, check the original notice and advisories applicable to your installed version; follow official update guidance and avoid processing untrusted files until you have assessed the exposure.

To consult and verify the source, search for identifier USN-8838-1 in the Ubuntu Security feed and check the cited CVE identifiers as well. If you use AI to study the notice or prepare internal procedures, share only what is necessary and remove personal data, credentials, and confidential information.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 5,00.

Try free