Heap-based buffer overflow in LibreOffice - CVE-2026-8357
Published: June 17, 2026
LibreOffice
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to heap-based buffer overflow in Calc formula compilation when parsing a specially crafted document containing a very long formula with many opening tokens. A remote attacker can trick the victim into opening a crafted document to execute arbitrary code.
User interaction is required to open a crafted document.