Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-6040

Опубликовано: 15 июн. 2026
Источник: redhat
CVSS3: 7.3

Описание

A heap use-after-free existed when importing the blank-width characters of an ODF number format. A position value read from the document was not checked against the length of the format-code string, so a malformed number format could be processed against memory outside that string. In fixed versions the position is bounds-checked before use.

A vulnerability was found in LibreOffice. If a user inadvertently opens a malicious OpenDocument Format (ODF) file, an attacker could execute unauthorized code and potentially gain full control of the system.

Отчет

This LibreOffice vulnerability is rated as Important. If a user inadvertently opens a maliciously crafted OpenDocument Format (ODF) file, an attacker can execute unauthorized code, potentially resulting in complete control over the affected system.

Меры по смягчению последствий

Users should exercise caution and avoid opening untrusted OpenDocument Format (ODF) files.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libreofficeOut of support scope
Red Hat Enterprise Linux 7libreofficeNot affected
Red Hat Enterprise Linux 8libreofficeNot affected
Red Hat Enterprise Linux 9libreofficeNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2488966libreoffice: LibreOffice: Heap use-after-free allows arbitrary code execution via malformed ODF number format

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 7.3
ubuntu
около 2 месяцев назад

A heap use-after-free existed when importing the blank-width characters of an ODF number format. A position value read from the document was not checked against the length of the format-code string, so a malformed number format could be processed against memory outside that string. In fixed versions the position is bounds-checked before use.

CVSS3: 7.3
nvd
около 2 месяцев назад

A heap use-after-free existed when importing the blank-width characters of an ODF number format. A position value read from the document was not checked against the length of the format-code string, so a malformed number format could be processed against memory outside that string. In fixed versions the position is bounds-checked before use.

CVSS3: 7.3
debian
около 2 месяцев назад

A heap use-after-free existed when importing the blank-width character ...

CVSS3: 7.3
github
около 2 месяцев назад

A heap use-after-free existed when importing the blank-width characters of an ODF number format. A position value read from the document was not checked against the length of the format-code string, so a malformed number format could be processed against memory outside that string. In fixed versions the position is bounds-checked before use.

suse-cvrf
14 дней назад

Security update for libreoffice

7.3 High

CVSS3