Junglewise Threat Intelligence

CVE-2026-63273: LibreOffice Draw heap buffer overflow in PDF import encryption handling

CVE-2026-63273 · Severity: info · Published 2026-09-22

Vendors: LibreOffice.

Executive brief

LibreOffice Draw includes a feature to import PDF documents. A heap buffer overflow vulnerability exists when processing encrypted PDFs: the application reads the encryption key length from the PDF's own dictionary without validating it against the fixed buffer size, allowing a malicious PDF to write data past the buffer boundary. An attacker who tricks a user into opening a specially crafted encrypted PDF could cause a crash or potentially achieve code execution on the user's system.

Technical details

The vulnerability is a classic heap buffer overflow in PDF import encryption handling due to insufficient bounds checking on the decryption key length. The key length is extracted from the document's encryption dictionary and used to fill a fixed-size buffer without validation, allowing writes beyond the buffer boundary. This requires user interaction (opening a document) and network delivery, but no authentication; the flaw was fixed in version 26.2.5 by rejecting declared key lengths that exceed the buffer size.

Affected products

  • LibreOffice Draw before 26.2.5

Timeline

  • 2026-09-21: disclosed
  • 2026-09-21: patched: Fixed in LibreOffice 26.2.5

References

Related threats