PT-2026-38345 · Document Foundation · Libreoffice

Danzation

+1

·

Published

2026-05-06

·

Updated

2026-05-15

·

CVE-2026-4430

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LibreOffice versions 26.2 through 26.2.2 LibreOffice versions 25.8 through 25.8.6
Description An out-of-bounds write occurs when processing crafted OOXML documents that contain mismatched encryption salt parameters. An out-of-bounds write is a memory corruption issue where data is written outside the intended boundary of a buffer, potentially leading to crashes or arbitrary code execution.
Recommendations Update LibreOffice versions 26.2 through 26.2.2 to version 26.2.3. Update LibreOffice versions 25.8 through 25.8.6 to version 25.8.7.

Fix

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2026-06581
CVE-2026-4430
ECHO-C13C-F4B9-2ECE

Affected Products

Libreoffice