Описание
LibreOffice Calc compiles cell formulas when opening a spreadsheet. A heap buffer overflow existed when compiling a very long formula made up of many opening tokens. The array that tracks nesting depth was allocated one element too small for that worst case, so such a formula wrote one element past its end. In fixed versions the array is sized to hold the largest possible nesting.
A vulnerability has been identified in LibreOffice Calc. An application crash may occur if a user opens a malicious spreadsheet that contains excessively long formulas. Successful exploitation of this vulnerability could result in a denial of service or potentially lead to arbitrary code execution.
Отчет
A vulnerability has been identified in LibreOffice Calc. An application crash may occur if a user opens a malicious spreadsheet that contains excessively long formulas. In severe cases, this could allow an attacker to run unauthorized, malicious code on the user's computer. Users should avoid opening untrusted spreadsheets
Меры по смягчению последствий
Users should exercise caution when opening untrusted or suspicious spreadsheet documents.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | libreoffice | Out of support scope | ||
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | libreoffice | Fixed | RHSA-2026:46386 | 27.07.2026 |
| Red Hat Enterprise Linux 8 | libreoffice | Fixed | RHSA-2026:35839 | 06.07.2026 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | libreoffice | Fixed | RHSA-2026:46387 | 27.07.2026 |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | libreoffice | Fixed | RHSA-2026:46387 | 27.07.2026 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | libreoffice | Fixed | RHSA-2026:43461 | 22.07.2026 |
| Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On | libreoffice | Fixed | RHSA-2026:43461 | 22.07.2026 |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | libreoffice | Fixed | RHSA-2026:43460 | 22.07.2026 |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | libreoffice | Fixed | RHSA-2026:43460 | 22.07.2026 |
| Red Hat Enterprise Linux 9 | libreoffice | Fixed | RHSA-2026:36832 | 08.07.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.8 High
CVSS3
Связанные уязвимости
LibreOffice Calc compiles cell formulas when opening a spreadsheet. A heap buffer overflow existed when compiling a very long formula made up of many opening tokens. The array that tracks nesting depth was allocated one element too small for that worst case, so such a formula wrote one element past its end. In fixed versions the array is sized to hold the largest possible nesting.
LibreOffice Calc compiles cell formulas when opening a spreadsheet. A heap buffer overflow existed when compiling a very long formula made up of many opening tokens. The array that tracks nesting depth was allocated one element too small for that worst case, so such a formula wrote one element past its end. In fixed versions the array is sized to hold the largest possible nesting.
LibreOffice Calc compiles cell formulas when opening a spreadsheet. A ...
EPSS
7.8 High
CVSS3