Heap Buffer Overflow Vulnerability in LibreOffice Document Processing
CVE-2026-63272
5.4MEDIUM
What is CVE-2026-63272?
LibreOffice experiences a heap buffer overflow vulnerability when importing WMF graphics within documents. Specifically, this issue arises from an inconsistency between the number of character advance values and the length of associated text. During text drawing, the application may inadvertently access memory beyond the end of the advance array, leading to potential exploitation. Fixed versions of LibreOffice address this by disregarding short advance arrays that mismatch their corresponding text lengths, thereby enhancing overall security.
Affected Version(s)
LibreOffice 26.2
References
CVSS V4
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Claude, found by Anthropic using agents to study the security of open-source projects
Ada Logics, validating and reporting
Caolán McNamara of Collabora Productivity
