Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-6045

Опубликовано: 15 июн. 2026
Источник: redhat
CVSS3: 6.6
EPSS Низкий

Описание

LibreOffice can import EMF+ graphics, which may be embedded in documents. A heap buffer overflow existed when importing an EMF+ gradient brush. The number of gradient blend points was read from the file and used to compute an allocation size, but that multiplication could overflow, so a small buffer was allocated and then filled as if it were large, writing past its end. In fixed versions the blend-point count is checked against the data actually available before allocating.

A flaw was found in LibreOffice. A heap buffer overflow exists when importing EMF+ graphics, which may be embedded in documents. An attacker could exploit this by convincing a user to open a specially crafted document. This could lead to denial of service or memory corruption, potentially allowing for arbitrary code execution.

Отчет

Moderate impact. This heap buffer overflow in LibreOffice's EMF+ graphics import requires user interaction to open a malicious document. While it could lead to denial of service or arbitrary code execution, the need for user interaction and the specific file format limits its immediate widespread impact on Red Hat Enterprise Linux desktop environments.

Меры по смягчению последствий

To reduce the risk of exploitation, users should avoid opening untrusted or suspicious documents with LibreOffice. This vulnerability requires user interaction to trigger the heap buffer overflow. While specific configuration to disable EMF+ graphics processing may not be readily available, running LibreOffice in a sandboxed environment can help limit the impact of a successful attack.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libreofficeOut of support scope
Red Hat Enterprise Linux 7libreofficeOut of support scope
Red Hat Enterprise Linux 8libreofficeFix deferred
Red Hat Enterprise Linux 9libreofficeFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2488957libreoffice: LibreOffice: Heap buffer overflow via crafted EMF+ graphics import

EPSS

Процентиль: 2%
0.0012
Низкий

6.6 Medium

CVSS3

Связанные уязвимости

ubuntu
около 2 месяцев назад

LibreOffice can import EMF+ graphics, which may be embedded in documents. A heap buffer overflow existed when importing an EMF+ gradient brush. The number of gradient blend points was read from the file and used to compute an allocation size, but that multiplication could overflow, so a small buffer was allocated and then filled as if it were large, writing past its end. In fixed versions the blend-point count is checked against the data actually available before allocating.

nvd
около 2 месяцев назад

LibreOffice can import EMF+ graphics, which may be embedded in documents. A heap buffer overflow existed when importing an EMF+ gradient brush. The number of gradient blend points was read from the file and used to compute an allocation size, but that multiplication could overflow, so a small buffer was allocated and then filled as if it were large, writing past its end. In fixed versions the blend-point count is checked against the data actually available before allocating.

debian
около 2 месяцев назад

LibreOffice can import EMF+ graphics, which may be embedded in documen ...

github
около 2 месяцев назад

LibreOffice can import EMF+ graphics, which may be embedded in documents. A heap buffer overflow existed when importing an EMF+ gradient brush. The number of gradient blend points was read from the file and used to compute an allocation size, but that multiplication could overflow, so a small buffer was allocated and then filled as if it were large, writing past its end. In fixed versions the blend-point count is checked against the data actually available before allocating.

EPSS

Процентиль: 2%
0.0012
Низкий

6.6 Medium

CVSS3