Executive brief
LibreOffice, a widely used open-source office suite, can read embedded CFF fonts in documents. A stack buffer overflow in font hint processing could allow an attacker to crash the application or potentially execute code by crafting a malicious document with a specially formatted CFF font. Users who open untrusted documents are at risk.
Technical details
A stack buffer overflow exists in LibreOffice's CFF font parsing when reading glyph hints. The hint count validation checked against an incorrect bound, allowing a glyph to declare more hints than the fixed-size array can hold, resulting in a stack write overflow. An attacker can trigger this via a malicious document containing an embedded CFF font with an excessive hint count.
Affected products
- LibreOffice LibreOffice before 26.2.5
Timeline
- 2026-09-21: disclosed
- 2026-09-22: patched: Fixed in LibreOffice 26.2.5