Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-8358

Опубликовано: 15 июн. 2026
Источник: redhat
CVSS3: 6.6
EPSS Низкий

Описание

LibreOffice Calc can import tracked changes from a spreadsheet document. A heap buffer overflow existed when a document reused the same change identifier for two different kinds of change. The importer then treated one change object as a different, larger type and wrote past the end of its allocation. In fixed versions records with a duplicate identifier are rejected.

A heap-based buffer overflow vulnerability was discovered in LibreOffice Calc's spreadsheet importer. When processing tracked changes from a spreadsheet document, the application fails to properly handle duplicate change identifiers. By reusing the same change identifier for two distinct types of change objects, a maliciously crafted document can trick the importer into treating a change object as a different, larger data type than originally allocated. This mismatch causes the importer to write data past the boundaries of the allocated heap buffer, which could result in a denial of service (application crash) or limited impacts to confidentiality and integrity under the privileges of the current user.

Отчет

This vulnerability affects LibreOffice Calc's tracked-changes import functionality. Red Hat Product Security has assessed this issue as a Moderate severity vulnerability. The flaw occurs when importing spreadsheet documents containing tracked-change records that reuse the same change identifier for different change types. Under these conditions, the importer may incorrectly treat a change object as a different, larger object type and write beyond the bounds of the allocated heap buffer. Successful exploitation requires a user to open a specially crafted spreadsheet document. A remote attacker could leverage this issue to cause application crashes resulting in denial of service and potentially achieve limited disclosure or modification of data within the context of the affected application.

Меры по смягчению последствий

Red Hat is not aware of a practical temporary workaround that fully mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libreofficeOut of support scope
Red Hat Enterprise Linux 7libreofficeOut of support scope
Red Hat Enterprise Linux 8libreofficeFix deferred
Red Hat Enterprise Linux 9libreofficeFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2488959LibreOffice: LibreOffice Calc: Heap buffer overflow leads to denial of service via crafted spreadsheet document.

EPSS

Процентиль: 7%
0.00171
Низкий

6.6 Medium

CVSS3

Связанные уязвимости

ubuntu
около 2 месяцев назад

LibreOffice Calc can import tracked changes from a spreadsheet document. A heap buffer overflow existed when a document reused the same change identifier for two different kinds of change. The importer then treated one change object as a different, larger type and wrote past the end of its allocation. In fixed versions records with a duplicate identifier are rejected.

nvd
около 2 месяцев назад

LibreOffice Calc can import tracked changes from a spreadsheet document. A heap buffer overflow existed when a document reused the same change identifier for two different kinds of change. The importer then treated one change object as a different, larger type and wrote past the end of its allocation. In fixed versions records with a duplicate identifier are rejected.

debian
около 2 месяцев назад

LibreOffice Calc can import tracked changes from a spreadsheet documen ...

github
около 2 месяцев назад

LibreOffice Calc can import tracked changes from a spreadsheet document. A heap buffer overflow existed when a document reused the same change identifier for two different kinds of change. The importer then treated one change object as a different, larger type and wrote past the end of its allocation. In fixed versions records with a duplicate identifier are rejected.

CVSS3: 6.6
fstec
около 2 месяцев назад

Уязвимость пакета офисных программ LibreOffice, связанная с переполнением буфера в динамической памяти, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 7%
0.00171
Низкий

6.6 Medium

CVSS3