Stack-based buffer overflow in LibreOffice - CVE-2026-8356
Published: June 17, 2026
LibreOffice
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to stack-based buffer overflow in PPT presentation import when parsing a crafted colour-replacement record. A remote attacker can trick the victim into opening a crafted presentation file to execute arbitrary code.
User interaction is required to open a crafted file.