CVE-2026-63272
Publication date 22 September 2026
Last updated 5 October 2026
Ubuntu priority
Description
LibreOffice can import WMF graphics, which may be embedded in documents. A heap buffer overflow existed when importing a text record that carries its own character advance widths. The count of advance values and the length of the text were read separately from the file and were not required to agree, so drawing the text walked the advance array by character position and ran past its end when the array was the shorter of the two. In fixed versions an advance array shorter than its text is ignored.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| libreoffice | 26.04 LTS resolute |
Fixed 4:26.2.6.3-0ubuntu0.26.04.2
|
| 24.04 LTS noble |
Fixed 4:24.2.7-0ubuntu0.24.04.7
|
|
| 22.04 LTS jammy |
Fixed 1:7.3.7-0ubuntu0.22.04.13
|
|
| 20.04 LTS focal |
Needs evaluation
|
Severity score breakdown
CVSS version: CVSS v4.0
Base score
5.4 · Medium
Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:P
References
Related Ubuntu Security Notices (USN)
- USN-8868-1
- LibreOffice vulnerabilities
- 5 October 2026