PT-2026-49265 · Document Foundation · Libreoffice

·

CVE-2026-6047

·

Published

2026-06-15

·

Updated

2026-07-20

CVSS v4.0

6.9

Medium

VectorAV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions LibreOffice (affected versions not specified)
Description A heap buffer overflow occurs during the import of documents in the OOXML (DOCX) format. The issue arises when replaying deferred parser events for a text box element, where a handler object is assumed to be of a specific type and written to according to that type's field layout. If the object is smaller than assumed, the write operation extends beyond the end of the memory allocation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Heap Based Buffer Overflow

Memory Corruption

Type Confusion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09483
CVE-2026-6047
ECHO-5250-FD80-297A
SUSE-SU-2026:3140-1

Affected Products

Libreoffice