Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-8357

Опубликовано: 15 июн. 2026
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

LibreOffice Calc compiles cell formulas when opening a spreadsheet. A heap buffer overflow existed when compiling a very long formula made up of many opening tokens. The array that tracks nesting depth was allocated one element too small for that worst case, so such a formula wrote one element past its end. In fixed versions the array is sized to hold the largest possible nesting.

A vulnerability has been identified in LibreOffice Calc. An application crash may occur if a user opens a malicious spreadsheet that contains excessively long formulas. Successful exploitation of this vulnerability could result in a denial of service or potentially lead to arbitrary code execution.

Отчет

A vulnerability has been identified in LibreOffice Calc. An application crash may occur if a user opens a malicious spreadsheet that contains excessively long formulas. In severe cases, this could allow an attacker to run unauthorized, malicious code on the user's computer. Users should avoid opening untrusted spreadsheets

Меры по смягчению последствий

Users should exercise caution when opening untrusted or suspicious spreadsheet documents.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libreofficeOut of support scope
Red Hat Enterprise Linux 7 Extended Lifecycle SupportlibreofficeFixedRHSA-2026:4638627.07.2026
Red Hat Enterprise Linux 8libreofficeFixedRHSA-2026:3583906.07.2026
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportlibreofficeFixedRHSA-2026:4638727.07.2026
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnlibreofficeFixedRHSA-2026:4638727.07.2026
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportlibreofficeFixedRHSA-2026:4346122.07.2026
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-OnlibreofficeFixedRHSA-2026:4346122.07.2026
Red Hat Enterprise Linux 8.8 Telecommunications Update ServicelibreofficeFixedRHSA-2026:4346022.07.2026
Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionslibreofficeFixedRHSA-2026:4346022.07.2026
Red Hat Enterprise Linux 9libreofficeFixedRHSA-2026:3683208.07.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-131
https://bugzilla.redhat.com/show_bug.cgi?id=2488964libreoffice: LibreOffice Calc: Arbitrary code execution via heap buffer overflow in formula compilation

EPSS

Процентиль: 5%
0.00157
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 2 месяцев назад

LibreOffice Calc compiles cell formulas when opening a spreadsheet. A heap buffer overflow existed when compiling a very long formula made up of many opening tokens. The array that tracks nesting depth was allocated one element too small for that worst case, so such a formula wrote one element past its end. In fixed versions the array is sized to hold the largest possible nesting.

CVSS3: 7.8
nvd
около 2 месяцев назад

LibreOffice Calc compiles cell formulas when opening a spreadsheet. A heap buffer overflow existed when compiling a very long formula made up of many opening tokens. The array that tracks nesting depth was allocated one element too small for that worst case, so such a formula wrote one element past its end. In fixed versions the array is sized to hold the largest possible nesting.

CVSS3: 7.8
debian
около 2 месяцев назад

LibreOffice Calc compiles cell formulas when opening a spreadsheet. A ...

rocky
21 день назад

Important: libreoffice security update

rocky
24 дня назад

Important: libreoffice security update

EPSS

Процентиль: 5%
0.00157
Низкий

7.8 High

CVSS3