Junglewise Threat Intelligence

CVE-2026-63272: LibreOffice heap buffer overflow in WMF text record import

CVE-2026-63272 · Severity: info · Published 2026-09-22

Technologies: LibreOffice. Vendors: LibreOffice.

Executive brief

LibreOffice processes embedded WMF graphics in documents. A heap buffer overflow vulnerability exists in the WMF text record importer when character advance width arrays are shorter than the text itself, potentially allowing memory corruption and crashes when a malicious document is opened.

Technical details

The vulnerability is a classic bounds check failure in WMF text record parsing: the count of advance width values and text length are read independently from the file without validation that they match. During rendering, the code iterates through characters and indexes the advance array by position, causing an out-of-bounds read/write when the array is exhausted before the text ends. The fix validates that advance arrays match text length and ignores shorter arrays.

Affected products

  • LibreOffice LibreOffice before 26.2.5

Timeline

  • 2026-09-21: disclosed
  • 2026-09-21: patched: Fixed in LibreOffice 26.2.5

References

Related threats