CVE-2026-6047
Announced: Jun 15, 2026
Fixed in: LibreOffice 26.2.3 and LibreOffice 25.8.7
Description:
A heap buffer overflow existed when replaying deferred parser events for a text box element. A handler object was assumed to be of one type and written to at that type’s field layout, but it could be a smaller object, so the write landed past the end of the allocation.
In fixed versions the type is checked before the write.
All users are recommended to upgrade to LibreOffice >= 26.2.3 or >= 25.8.7 to avoid this problem.
Credits:
Thanks to Anthropic for discovering this issue using automated analysis with Claude.
Thanks to Trail of Bits for triaging and validating this issue.
Thanks to Caolán McNamara of Collabora Productivity for providing a fix.
References:

Sledujte nás