Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-6040

Опубликовано: 15 июн. 2026
Источник: ubuntu
Приоритет: medium
CVSS3: 7.3

Описание

A heap use-after-free existed when importing the blank-width characters of an ODF number format. A position value read from the document was not checked against the length of the format-code string, so a malformed number format could be processed against memory outside that string. In fixed versions the position is bounds-checked before use.

РелизСтатусПримечание
devel

not-affected

4:26.2.4.2-0ubuntu1
esm-infra/focal

not-affected

code not present
jammy

not-affected

code not present
noble

released

4:24.2.7-0ubuntu0.24.04.6
questing

ignored

end of life, was needs-triage
resolute

released

4:26.2.4.2-0ubuntu0.26.04.2
upstream

released

26.2.3,25.8.7

Показывать по

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 7.3
redhat
около 2 месяцев назад

A heap use-after-free existed when importing the blank-width characters of an ODF number format. A position value read from the document was not checked against the length of the format-code string, so a malformed number format could be processed against memory outside that string. In fixed versions the position is bounds-checked before use.

CVSS3: 7.3
nvd
около 2 месяцев назад

A heap use-after-free existed when importing the blank-width characters of an ODF number format. A position value read from the document was not checked against the length of the format-code string, so a malformed number format could be processed against memory outside that string. In fixed versions the position is bounds-checked before use.

CVSS3: 7.3
debian
около 2 месяцев назад

A heap use-after-free existed when importing the blank-width character ...

CVSS3: 7.3
github
около 2 месяцев назад

A heap use-after-free existed when importing the blank-width characters of an ODF number format. A position value read from the document was not checked against the length of the format-code string, so a malformed number format could be processed against memory outside that string. In fixed versions the position is bounds-checked before use.

suse-cvrf
14 дней назад

Security update for libreoffice

7.3 High

CVSS3

Уязвимость CVE-2026-6040