PT-2026-38345 · Document Foundation+3 · Libreoffice+3

·

CVE-2026-4430

·

Published

2026-05-06

·

Updated

2026-07-20

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LibreOffice versions 26.2 through 26.2.2 LibreOffice versions 25.8 through 25.8.6
Description An out-of-bounds write occurs when processing crafted OOXML documents that contain mismatched encryption salt parameters. An out-of-bounds write is a memory corruption issue where data is written outside the intended boundary of a buffer, potentially leading to crashes or arbitrary code execution.
Recommendations Update LibreOffice versions 26.2 through 26.2.2 to version 26.2.3. Update LibreOffice versions 25.8 through 25.8.6 to version 25.8.7.

Fix

DoS

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:28290
ALSA-2026:28922
BDU:2026-06581
CVE-2026-4430
ECHO-C13C-F4B9-2ECE
MGASA-2026-0141
RHSA-2026:28290
RHSA-2026:28922
RHSA-2026:37249
RHSA-2026:37250
RHSA-2026:37251
RHSA-2026:38507
RHSA-2026:38508
RHSA-2026:39119
SUSE-SU-2026:3140-1
USN-8340-1
USN-8352-1

Affected Products

Libreoffice
Linuxmint
Rocky Linux
Ubuntu