SB2026061752 - Multiple vulnerabilities in LibreOffice



SB2026061752 - Multiple vulnerabilities in LibreOffice

Published: June 17, 2026

Security Bulletin ID SB2026061752
CSH Severity
High
Patch available
YES
Number of vulnerabilities 7
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 86% Low 14%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 7 vulnerabilities.


1) Stack-based buffer overflow (CVE-ID: CVE-2026-8356)

CWE-ID: CWE-121 - Stack-based buffer overflow

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to stack-based buffer overflow in PPT presentation import when parsing a crafted colour-replacement record. A remote attacker can trick the victim into opening a crafted presentation file to execute arbitrary code.

User interaction is required to open a crafted file.


2) Heap-based buffer overflow (CVE-ID: CVE-2026-8357)

CWE-ID: CWE-122 - Heap-based Buffer Overflow

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to heap-based buffer overflow in Calc formula compilation when parsing a specially crafted document containing a very long formula with many opening tokens. A remote attacker can trick the victim into opening a crafted document to execute arbitrary code.

User interaction is required to open a crafted document.


3) Heap-based buffer overflow (CVE-ID: CVE-2026-8358)

CWE-ID: CWE-122 - Heap-based Buffer Overflow

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to heap-based buffer overflow in spreadsheet tracked-changes importer when parsing a crafted spreadsheet document with reused change identifiers. A remote attacker can trick the victim into opening a specially crafted file to execute arbitrary code.

User interaction is required to open a crafted spreadsheet document.


4) Use-after-free (CVE-ID: CVE-2026-6040)

CWE-ID: CWE-416 - Use After Free

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to use-after-free in ODF number-format blank-width parsing when importing a crafted ODF document. A remote attacker can trick the victim into opening a crafted file to cause a denial of service.

The issue occurs when processing number format data that pads a number with blank space as wide as a chosen character.


5) Heap-based buffer overflow (CVE-ID: CVE-2026-6039)

CWE-ID: CWE-122 - Heap-based Buffer Overflow

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to heap-based buffer overflow in DXF polyline import when parsing a crafted DXF file. A remote attacker can trick the victim into opening a specially crafted file to execute arbitrary code.

The issue occurs when a polyline point count exceeds the 16-bit range, causing the buffer to be sized using a truncated value while writes use the full count.


6) Heap-based buffer overflow (CVE-ID: CVE-2026-6045)

CWE-ID: CWE-122 - Heap-based Buffer Overflow

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to heap-based buffer overflow in EMF+ gradient brush import when parsing a crafted document. A remote attacker can trick the victim into opening a specially crafted file to execute arbitrary code.

User interaction is required to open a crafted file.


7) Heap-based buffer overflow (CVE-ID: CVE-2026-6047)

CWE-ID: CWE-122 - Heap-based Buffer Overflow

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to a heap-based buffer overflow in the OOXML text box element import logic when replaying deferred parser events while parsing a crafted document. A remote attacker can trick the victim into opening a specially crafted file to execute arbitrary code.

User interaction is required to open a crafted file.


Remediation

Install update from vendor's website.