Use-after-free in LibreOffice - CVE-2026-6040
Published: June 17, 2026
LibreOffice
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to use-after-free in ODF number-format blank-width parsing when importing a crafted ODF document. A remote attacker can trick the victim into opening a crafted file to cause a denial of service.
The issue occurs when processing number format data that pads a number with blank space as wide as a chosen character.