Stack Buffer Overflow Vulnerability in LibreOffice CFF Font Handling
CVE-2026-63275
5.4MEDIUM
What is CVE-2026-63275?
A stack buffer overflow vulnerability exists in LibreOffice's handling of CFF fonts embedded in documents. This issue arises during the processing of glyph hints, where the check for the number of hints against the buffer's capacity is inadequate. As a result, if a glyph declares more hints than the allocated array can accommodate, it can lead to a write operation beyond the expected bounds, creating potential exploit pathways in affected versions.
Affected Version(s)
LibreOffice 26.2
References
CVSS V4
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Claude, found by Anthropic using agents to study the security of open-source projects
Ada Logics, validating and reporting
Caolán McNamara of Collabora Productivity
