USN-8868-1: LibreOffice vulnerabilities
Ubuntu's USN-8868-1 fixes LibreOffice flaws that could crash the app or execute code.
Ubuntu security notice USN-8868-1 says LibreOffice mishandled several document inputs in ways that could crash the application or allow arbitrary code execution. CVE-2026-63272 concerns WMF image imports. CVE-2026-63273 and CVE-2026-63274 concern PDF document imports. The notice also says embedded CFF fonts were handled incorrectly, with the same possible crash or code-execution impact. The text does not report exploitation in the wild.
- USN-8868-1 covers LibreOffice import and font-handling flaws.
- CVE-2026-63272 affects WMF image imports.
- CVE-2026-63273 and CVE-2026-63274 affect PDF document imports.
- Impact described as denial of service or possible arbitrary code execution.
Vulnerabilities mentionedAll →
- CVE-2026-632725.4—Heap buffer overflow in LibreOffice WMF text importpublished · The Document Foundation LibreOffice
- CVE-2026-632735.4—Heap buffer overflow in LibreOffice Draw PDF importpublished · The Document Foundation LibreOffice Draw+1 related
| CVE | Vulnerability |
|---|
It was discovered that LibreOffice incorrectly handled WMF image imports. An attacker could possibly use this issue to cause LibreOffice to crash, resulting in a denial of service, or execute arbitrary code. (CVE-2026-63272) It was discovered that LibreOffice incorrectly handled PDF document imports. An attacker could possibly use this issue to cause LibreOffice to crash, resulting in a denial of service, or execute arbitrary code. (CVE-2026-63273, CVE-2026-63274) It was discovered that LibreOffice incorrectly handled CFF fonts embedded in documents. An attacker could possibly use this issue to cause LibreOffice to crash, resulting in a denial of service, or execute arbitrary code.…
This source does not provide full text. Read it at ubuntu.com.