Ce mail provient de l'extérieur, restons vigilants ===================================================================== CERT-Renater Note d'Information No. 2026/VULN931 _____________________________________________________________________ DATE : 25/09/2026 HARDWARE PLATFORM(S): / OPERATING SYSTEM(S): Systems running LibreOffice versions prior to 26.2.5. ===================================================================== https://www.libreoffice.org/security/ _____________________________________________________________________ CVE-2026-63272 Heap buffer overflow in WMF text record import Announced: Sep 21, 2026 Fixed in: LibreOffice 26.2.5 Description: LibreOffice can import WMF graphics, which may be embedded in documents. A heap buffer overflow existed when importing a text record that carries its own character advance widths. The count of advance values and the length of the text were read separately from the file and were not required to agree, so drawing the text walked the advance array by character position and ran past its end when the array was the shorter of the two. In fixed versions an advance array shorter than its text is ignored. All users are recommended to upgrade to LibreOffice >= 26.2.5 to avoid this problem. Credits: Thanks to Claude and Ada Logics – found by Anthropic using agents to study the security of open-source projects, with Ada Logics validating and reporting. Thanks to Caolán McNamara of Collabora Productivity for providing the fix. References: CVE-2026-63272 _____________________________________________________________________ Announced: Sep 21, 2026 Fixed in: LibreOffice 26.2.5 Description: LibreOffice Draw can import PDF documents. A heap buffer overflow existed when importing an encrypted document. The length of the decryption key was taken from the document’s own encryption dictionary and was used to fill a fixed size key buffer without being checked against it, so a length larger than that buffer wrote past its end. In fixed versions a declared key length larger than the buffer is rejected. All users are recommended to upgrade to LibreOffice >= 26.2.5 to avoid this problem. Credits: Thanks to Claude and Ada Logics – found by Anthropic using agents to study the security of open-source projects, with Ada Logics validating and reporting. Thanks to Caolán McNamara of Collabora Productivity for providing the fix. References: CVE-2026-63273 _____________________________________________________________________ Announced: Sep 21, 2026 Fixed in: LibreOffice 26.2.5 Description: LibreOffice Draw can import PDF documents. A heap buffer overflow existed when importing a stream object. The length of the stream was taken from the object’s own dictionary and was not checked against the number of bytes actually present, so copying the stream read and wrote past the end of the buffer holding it. In fixed versions the declared length is clamped to the bytes actually read. All users are recommended to upgrade to LibreOffice >= 26.2.5 to avoid this problem. Credits: Thanks to Claude and Ada Logics – found by Anthropic using agents to study the security of open-source projects, with Ada Logics validating and reporting. Thanks to Caolán McNamara of Collabora Productivity for providing the fix. References: CVE-2026-63274 _____________________________________________________________________ Announced: Sep 21, 2026 Fixed in: LibreOffice 26.2.5 Description: LibreOffice can read CFF fonts, which may be embedded in documents. A stack buffer overflow existed when reading the hints of a glyph. The number of hints was checked against the wrong bound, so a glyph declaring more hints than the array can hold wrote past its end. In fixed versions the hint count is checked against the capacity the array really has. All users are recommended to upgrade to LibreOffice >= 26.2.5 to avoid this problem. Credits: Thanks to Claude and Ada Logics – found by Anthropic using agents to study the security of open-source projects, with Ada Logics validating and reporting. Thanks to Caolán McNamara of Collabora Productivity for providing the fix. References: CVE-2026-63275 _____________________________________________________________________ Announced: Sep 21, 2026 Fixed in: LibreOffice 26.2.5 Description: LibreOffice converts CFF fonts to Type 1 when it subsets a font, which happens when a document is exported to PDF, and CFF fonts may be embedded in documents. A stack buffer overflow existed in that conversion. The converted operators were written into a fixed size buffer with no check that they still fit, so a glyph emitting many operators wrote past the end of the buffer. In fixed versions the remaining capacity is tracked and the conversion stops when it is used up. All users are recommended to upgrade to LibreOffice >= 26.2.5 to avoid this problem. Credits: Thanks to Claude and Ada Logics – found by Anthropic using agents to study the security of open-source projects, with Ada Logics validating and reporting. Thanks to Caolán McNamara of Collabora Productivity for providing the fix. References: CVE-2026-63276 _____________________________________________________________________ Announced: Sep 21, 2026 Fixed in: LibreOffice 26.2.5 Description: URLs could be constructed which expanded environment variable or INI file values, so potentially sensitive information could be exfiltrated to a remote server on opening a document containing such links. The check added for CVE-2024-12426 did not recognise every way of naming the package content provider, so a URL that named it differently still reached the expansion. In fixed versions the package content provider is matched when the URL is checked. All users are recommended to upgrade to LibreOffice >= 26.2.5 to avoid this problem. Credits: Thanks to Darren Xuan of Tanto Security for reporting this issue. Thanks to Caolán McNamara of Collabora Productivity for providing the fix. References: CVE-2026-63278 _____________________________________________________________________ Announced: Sep 21, 2026 Fixed in: LibreOffice 26.2.5 Description: LibreOffice can import PICT images, which may be embedded in documents. An out of bounds read existed when importing an image that uses a colour palette. The palette index held in the image data was used without being checked against the number of entries the palette has, so an index past the last entry read memory outside the palette. In fixed versions the palette index is limited to the entries present. All users are recommended to upgrade to LibreOffice >= 26.2.5 to avoid this problem. Credits: Thanks to Himanshu Anand for reporting this issue. Thanks to Caolán McNamara of Collabora Productivity for providing the fix. References: CVE-2026-63279 ========================================================= + CERT-RENATER | tel : 01-53-94-20-44 + + 23/25 Rue Daviel | fax : 01-53-94-20-41 + + 75013 Paris | email:cert@support.renater.fr + =========================================================