PT-2026-96701 · Document Foundation · Libreoffice

·

CVE-2026-63272

·

Published

2026-09-22

·

Updated

2026-09-22

CVSS v4.0

6.9

Medium

VectorAV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions LibreOffice (affected versions not specified)
Description An issue exists when importing WMF (Windows Metafile) graphics embedded in documents. A heap buffer overflow occurs during the import of a text record that includes its own character advance widths. This happens because the count of advance values and the text length are read separately from the file without validation to ensure they agree. Consequently, drawing the text can cause the process to read past the end of the advance array if the array is shorter than the text length.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Out of bounds Read

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63272

Affected Products

Libreoffice