Out of Bounds Read Vulnerability in LibreOffice Image Import
CVE-2026-63279

5.4MEDIUM

Key Information:

Vendor
CVE Published:
22 September 2026

What is CVE-2026-63279?

LibreOffice has a vulnerability related to its image import functionality, specifically when handling PICT images. The issue arises from an out of bounds read that occurs when an image utilizes a color palette. During the import process, the palette index from the image data may not be properly validated against the actual number of entries available in the palette. This can lead to access of memory locations beyond the intended data, raising significant security concerns. Fixed versions address this by ensuring the palette index is constrained to the existing entries, mitigating potential exploitation.

Affected Version(s)

LibreOffice 26.2

References

CVSS V4

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Himanshu Anand
Caolán McNamara of Collabora Productivity
.