Integer Underflow Vulnerability in osslsigncode Tool by mTrojnar
CVE-2026-39855

5.5MEDIUM

Key Information:

Vendor

Mtrojnar

Vendor
CVE Published:
9 April 2026

What is CVE-2026-39855?

An integer underflow vulnerability was identified in osslsigncode prior to version 2.13. This issue arises during the PE page-hash computation within the pe_page_hash_calc() function, where a maliciously crafted PE file could exploit improper validation of header and section sizes. The vulnerability allows attackers to cause out-of-bounds reads from memory, potentially leading to application crashes during the signing or verification of PE files with page hashing enabled. It is crucial to update to version 2.13 or later to mitigate this risk.

Affected Version(s)

osslsigncode < 2.13

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.