Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-4430

Опубликовано: 07 мая 2026
Источник: redhat
CVSS3: 7.6
EPSS Низкий

Описание

Out-of-bounds write vulnerability in The Document Foundation LibreOffice via crafted OOXML documents with mismatched encryption salt parameters. This issue affects LibreOffice: from 26.2 before 26.2.3, from 25.8 before 25.8.7.

A flaw was found in LibreOffice. A remote attacker could exploit this out-of-bounds write vulnerability by tricking a user into opening a specially crafted OOXML (Office Open XML) document with mismatched encryption salt parameters. This could lead to a denial of service (DoS), making the application unavailable, and potentially result in limited information disclosure or integrity impact.

Меры по смягчению последствий

Users are advised to avoid opening untrusted or suspicious OOXML documents. This operational control reduces the risk of exploitation by preventing the vulnerable LibreOffice component from processing malicious input.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libreofficeWill not fix
Red Hat Enterprise Linux 7 Extended Lifecycle SupportlibreofficeFixedRHSA-2026:4638627.07.2026
Red Hat Enterprise Linux 8libreofficeFixedRHSA-2026:2892224.06.2026
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportlibreofficeFixedRHSA-2026:3724909.07.2026
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnlibreofficeFixedRHSA-2026:3724909.07.2026
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportlibreofficeFixedRHSA-2026:3911914.07.2026
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-OnlibreofficeFixedRHSA-2026:3911914.07.2026
Red Hat Enterprise Linux 8.8 Telecommunications Update ServicelibreofficeFixedRHSA-2026:3725109.07.2026
Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionslibreofficeFixedRHSA-2026:3725109.07.2026
Red Hat Enterprise Linux 9libreofficeFixedRHSA-2026:2829024.06.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2467657LibreOffice: LibreOffice: Denial of Service via crafted OOXML documents

EPSS

Процентиль: 0%
0.00078
Низкий

7.6 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
3 месяца назад

Out-of-bounds write vulnerability in The Document Foundation LibreOffice via crafted OOXML documents with mismatched encryption salt parameters. This issue affects LibreOffice: from 26.2 before 26.2.3, from 25.8 before 25.8.7.

CVSS3: 7.8
nvd
3 месяца назад

Out-of-bounds write vulnerability in The Document Foundation LibreOffice via crafted OOXML documents with mismatched encryption salt parameters. This issue affects LibreOffice: from 26.2 before 26.2.3, from 25.8 before 25.8.7.

CVSS3: 7.8
debian
3 месяца назад

Out-of-bounds write vulnerability in The Document Foundation LibreOffi ...

rocky
около 1 месяца назад

Moderate: libreoffice security update

CVSS3: 7.8
github
3 месяца назад

Out-of-bounds write vulnerability in The Document Foundation LibreOffice via crafted OOXML documents with mismatched encryption salt parameters. This issue affects LibreOffice: from 26.2 before 26.2.3, from 25.8 before 25.8.7.

EPSS

Процентиль: 0%
0.00078
Низкий

7.6 High

CVSS3