Описание
Out-of-bounds write vulnerability in The Document Foundation LibreOffice via crafted OOXML documents with mismatched encryption salt parameters.
This issue affects LibreOffice: from 26.2 before 26.2.3, from 25.8 before 25.8.7.
A flaw was found in LibreOffice. A remote attacker could exploit this out-of-bounds write vulnerability by tricking a user into opening a specially crafted OOXML (Office Open XML) document with mismatched encryption salt parameters. This could lead to a denial of service (DoS), making the application unavailable, and potentially result in limited information disclosure or integrity impact.
Меры по смягчению последствий
Users are advised to avoid opening untrusted or suspicious OOXML documents. This operational control reduces the risk of exploitation by preventing the vulnerable LibreOffice component from processing malicious input.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | libreoffice | Will not fix | ||
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | libreoffice | Fixed | RHSA-2026:46386 | 27.07.2026 |
| Red Hat Enterprise Linux 8 | libreoffice | Fixed | RHSA-2026:28922 | 24.06.2026 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | libreoffice | Fixed | RHSA-2026:37249 | 09.07.2026 |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | libreoffice | Fixed | RHSA-2026:37249 | 09.07.2026 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | libreoffice | Fixed | RHSA-2026:39119 | 14.07.2026 |
| Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On | libreoffice | Fixed | RHSA-2026:39119 | 14.07.2026 |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | libreoffice | Fixed | RHSA-2026:37251 | 09.07.2026 |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | libreoffice | Fixed | RHSA-2026:37251 | 09.07.2026 |
| Red Hat Enterprise Linux 9 | libreoffice | Fixed | RHSA-2026:28290 | 24.06.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.6 High
CVSS3
Связанные уязвимости
Out-of-bounds write vulnerability in The Document Foundation LibreOffice via crafted OOXML documents with mismatched encryption salt parameters. This issue affects LibreOffice: from 26.2 before 26.2.3, from 25.8 before 25.8.7.
Out-of-bounds write vulnerability in The Document Foundation LibreOffice via crafted OOXML documents with mismatched encryption salt parameters. This issue affects LibreOffice: from 26.2 before 26.2.3, from 25.8 before 25.8.7.
Out-of-bounds write vulnerability in The Document Foundation LibreOffi ...
Out-of-bounds write vulnerability in The Document Foundation LibreOffice via crafted OOXML documents with mismatched encryption salt parameters. This issue affects LibreOffice: from 26.2 before 26.2.3, from 25.8 before 25.8.7.
EPSS
7.6 High
CVSS3