{"id":"CVE-2026-39853","summary":"osslsigncode has a Stack Buffer Overflow via Unbounded Digest Copy During Signature Verification","details":"osslsigncode is a tool that implements Authenticode signing and timestamping. Prior to 2.12, A stack buffer overflow vulnerability exists in osslsigncode in several signature verification paths. During verification of a PKCS#7 signature, the code copies the digest value from a parsed SpcIndirectDataContent structure into a fixed-size stack buffer  (mdbuf[EVP_MAX_MD_SIZE], 64 bytes) without validating that the source length fits within the destination buffer. This pattern is present in the verification handlers for PE, MSI, CAB, and script files. An attacker can craft a malicious signed file with an oversized digest field in SpcIndirectDataContent. When a user verifies such a file with osslsigncode verify, the unbounded memcpy can overflow the stack buffer and corrupt adjacent stack state. This vulnerability is fixed in 2.12.","aliases":["GHSA-hx87-8754-xvh4"],"modified":"2026-08-12T16:23:58.289345Z","published":"2026-04-09T15:50:26.548Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-121","CWE-787"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/39xxx/CVE-2026-39853.json"},"references":[{"type":"WEB","url":"https://github.com/mtrojnar/osslsigncode/releases/tag/2.12"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/39xxx/CVE-2026-39853.json"},{"type":"ADVISORY","url":"https://github.com/mtrojnar/osslsigncode/security/advisories/GHSA-hx87-8754-xvh4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-39853"},{"type":"FIX","url":"https://github.com/mtrojnar/osslsigncode/commit/cbee1e723c5a8547302bd841ad9943ed8144db68"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/mtrojnar/osslsigncode","events":[{"introduced":"0"},{"fixed":"fac81646228a4d58aa9df41ac2b84c5a21d9d2d9"},{"fixed":"cbee1e723c5a8547302bd841ad9943ed8144db68"}],"database_specific":{"cpe":"cpe:2.3:a:osslsigncode_project:osslsigncode:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"2.12"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["2.11","2.10","2.9","2.8","2.7","2.6","2.5","2.4","2.3","2.2","2.1","2.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-39853.json","vanir_signatures_modified":"2026-08-12T16:23:58Z","vanir_signatures":[{"id":"CVE-2026-39853-1c46e99e","signature_type":"Function","signature_version":"v1","source":"https://github.com/mtrojnar/osslsigncode/commit/cbee1e723c5a8547302bd841ad9943ed8144db68","target":{"file":"msi.c","function":"msi_verify_digests"},"deprecated":false,"digest":{"length":3442,"function_hash":"7082838060947355442102594181268479517"}},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/mtrojnar/osslsigncode/commit/cbee1e723c5a8547302bd841ad9943ed8144db68","target":{"file":"helpers.h"},"deprecated":false,"digest":{"line_hashes":["135713086926393218447926872216326261372","199914932917842896028731767519076129123"],"threshold":0.9},"id":"CVE-2026-39853-245900bc"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/mtrojnar/osslsigncode/commit/cbee1e723c5a8547302bd841ad9943ed8144db68","target":{"file":"cat.c"},"deprecated":false,"digest":{"line_hashes":["68415973127219734331714277347035975712","325540716297678602498258335186037007802","140759284760969063668494452973539589512","337882276697824980006384321900902187802","115427071862798010042693710436358850595","67522959823450650990004599689480862185"],"threshold":0.9},"id":"CVE-2026-39853-25e54eff"},{"deprecated":false,"digest":{"function_hash":"330075126843529403136055493081121401","length":840},"id":"CVE-2026-39853-496a7c8c","signature_type":"Function","signature_version":"v1","source":"https://github.com/mtrojnar/osslsigncode/commit/cbee1e723c5a8547302bd841ad9943ed8144db68","target":{"file":"cat.c","function":"cat_print_content_member_digest"}},{"deprecated":false,"digest":{"line_hashes":["294196164287761961589666703434750257173","60495124532956490106045270096232172204","151216767925243767661756542210958922717","337882276697824980006384321900902187802","115427071862798010042693710436358850595","165970862720636573206245504323385944522"],"threshold":0.9},"id":"CVE-2026-39853-4c28ce3e","signature_type":"Line","signature_version":"v1","source":"https://github.com/mtrojnar/osslsigncode/commit/cbee1e723c5a8547302bd841ad9943ed8144db68","target":{"file":"msi.c"}},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/mtrojnar/osslsigncode/commit/cbee1e723c5a8547302bd841ad9943ed8144db68","target":{"file":"pe.c","function":"pe_verify_digests"},"deprecated":false,"digest":{"function_hash":"98387009644364892356896584865388264656","length":1556},"id":"CVE-2026-39853-63fe31a9"},{"digest":{"line_hashes":["177243898153687793868340892984033007942","188228084852164090110183459134525021076","222957626769235363520763389406175655106","337882276697824980006384321900902187802","211883438698217851110911666084850698172","209386534667382533773141099439571757428"],"threshold":0.9},"id":"CVE-2026-39853-7edc3891","signature_type":"Line","signature_version":"v1","source":"https://github.com/mtrojnar/osslsigncode/commit/cbee1e723c5a8547302bd841ad9943ed8144db68","target":{"file":"osslsigncode.c"},"deprecated":false},{"deprecated":false,"digest":{"function_hash":"317210793094659141246130368244393693107","length":1118},"id":"CVE-2026-39853-95e8b7e0","signature_type":"Function","signature_version":"v1","source":"https://github.com/mtrojnar/osslsigncode/commit/cbee1e723c5a8547302bd841ad9943ed8144db68","target":{"function":"cab_verify_digests","file":"cab.c"}},{"source":"https://github.com/mtrojnar/osslsigncode/commit/cbee1e723c5a8547302bd841ad9943ed8144db68","target":{"file":"helpers.c"},"deprecated":false,"digest":{"line_hashes":["36272731860730000053498603403996601283","85397026836763774827995722626512084907","272474611131647023760888946609624306382"],"threshold":0.9},"id":"CVE-2026-39853-ace119bd","signature_type":"Line","signature_version":"v1"},{"digest":{"line_hashes":["294196164287761961589666703434750257173","60495124532956490106045270096232172204","151216767925243767661756542210958922717","337882276697824980006384321900902187802","115427071862798010042693710436358850595","165970862720636573206245504323385944522"],"threshold":0.9},"id":"CVE-2026-39853-d31659a0","signature_type":"Line","signature_version":"v1","source":"https://github.com/mtrojnar/osslsigncode/commit/cbee1e723c5a8547302bd841ad9943ed8144db68","target":{"file":"script.c"},"deprecated":false},{"source":"https://github.com/mtrojnar/osslsigncode/commit/cbee1e723c5a8547302bd841ad9943ed8144db68","target":{"file":"script.c","function":"script_verify_digests"},"deprecated":false,"digest":{"function_hash":"297053246920564782174884000374205904393","length":1193},"id":"CVE-2026-39853-e2a27dba","signature_type":"Function","signature_version":"v1"},{"target":{"file":"osslsigncode.c","function":"verify_content_member_digest"},"deprecated":false,"digest":{"function_hash":"162772363341062063893543784638959021372","length":1717},"id":"CVE-2026-39853-e5f53135","signature_type":"Function","signature_version":"v1","source":"https://github.com/mtrojnar/osslsigncode/commit/cbee1e723c5a8547302bd841ad9943ed8144db68"},{"source":"https://github.com/mtrojnar/osslsigncode/commit/cbee1e723c5a8547302bd841ad9943ed8144db68","target":{"file":"cab.c"},"deprecated":false,"digest":{"line_hashes":["294196164287761961589666703434750257173","60495124532956490106045270096232172204","151216767925243767661756542210958922717","337882276697824980006384321900902187802","115427071862798010042693710436358850595","165970862720636573206245504323385944522"],"threshold":0.9},"id":"CVE-2026-39853-eb077b2a","signature_type":"Line","signature_version":"v1"},{"source":"https://github.com/mtrojnar/osslsigncode/commit/cbee1e723c5a8547302bd841ad9943ed8144db68","target":{"file":"pe.c"},"deprecated":false,"digest":{"line_hashes":["213052994559488522703551477998432787905","144174570826663442529232161926665724338","222957626769235363520763389406175655106","337882276697824980006384321900902187802","115427071862798010042693710436358850595","165970862720636573206245504323385944522"],"threshold":0.9},"id":"CVE-2026-39853-efe8cca2","signature_type":"Line","signature_version":"v1"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}