Stack Buffer Overflow in LibreOffice Due to Font Conversion Issue
CVE-2026-63276

5.4MEDIUM

Key Information:

Vendor
CVE Published:
22 September 2026

What is CVE-2026-63276?

A vulnerability exists in LibreOffice related to the conversion of CFF fonts to Type 1 during the PDF export process. The flaw arises when the application subsets fonts, leading to a stack buffer overflow due to inadequate size checking of the fixed buffer. Consequently, if the font glyph emits numerous operators, they can overflow past the buffer's end, potentially compromising system security. Recent patches implement capacity tracking to prevent such overflows during the conversion process.

Affected Version(s)

LibreOffice 26.2

References

CVSS V4

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Claude, found by Anthropic using agents to study the security of open-source projects
Ada Logics, validating and reporting
Caolán McNamara of Collabora Productivity
.