CVE-2026-63275

Publication date 22 September 2026

Last updated 5 October 2026


Ubuntu priority

Description

LibreOffice can read CFF fonts, which may be embedded in documents. A stack buffer overflow existed when reading the hints of a glyph. The number of hints was checked against the wrong bound, so a glyph declaring more hints than the array can hold wrote past its end. In fixed versions the hint count is checked against the capacity the array really has.

Status

Package Ubuntu Release Status
libreoffice 26.04 LTS resolute
Fixed 4:26.2.6.3-0ubuntu0.26.04.2
24.04 LTS noble
Fixed 4:24.2.7-0ubuntu0.24.04.7
22.04 LTS jammy
Fixed 1:7.3.7-0ubuntu0.22.04.13
20.04 LTS focal
Needs evaluation

Severity score breakdown

CVSS version: CVSS v4.0

Base score 5.4 · Medium

Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:P


Access our resources on patching vulnerabilities