Heap Use-After-Free Flaw in Gnumeric by GNOME
CVE-2026-97222

5.5MEDIUM

Key Information:

Vendor

Gnome

Status
Vendor
CVE Published:
25 September 2026

What is CVE-2026-97222?

A heap use-after-free issue exists in Gnumeric, triggered when a user opens a specially crafted workbook with a malformed SheetObjectComponent element. This flaw can cause the XML parser to dereference a freed sheet-object component, leading to application crashes. It emphasizes the importance of careful handling of memory management within the software to mitigate potential disruption to users.

Affected Version(s)

Gnumeric 1.11.0

Gnumeric bc1dee29525933994181fb2307d6ad584de6040d

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Upstream acknowledges Juha Kylmänen as the original reporter.
.