PT-2026-49265 · Document Foundation · Libreoffice
Anthropic
+1
·
Published
2026-06-15
·
Updated
2026-06-15
·
CVE-2026-6047
CVSS v4.0
6.9
Medium
| Vector | AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
LibreOffice (affected versions not specified)
Description
A heap buffer overflow occurs during the import of documents in the OOXML (DOCX) format. The issue arises when replaying deferred parser events for a text box element, where a handler object is assumed to be of a specific type and written to according to that type's field layout. If the object is smaller than assumed, the write operation extends beyond the end of the memory allocation.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Memory Corruption
Type Confusion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Libreoffice