Out-of-Bounds Write Vulnerability in LibreOffice by The Document Foundation
CVE-2026-4430
5.4MEDIUM
What is CVE-2026-4430?
An out-of-bounds write vulnerability exists in The Document Foundation's LibreOffice, which could be triggered by processing specially crafted OOXML documents that contain mismatched encryption salt parameters. This flaw potentially allows attackers to overwrite memory and execute arbitrary code, jeopardizing user data and system stability.
Affected Version(s)
LibreOffice 26.2 < 26.2.3
LibreOffice 25.8 < 25.8.7
References
CVSS V4
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Duc Anh Nguyen (@Danzation)
Caolán McNamara <caolan.mcnamara@collabora.com>
