CVE-2025-2866
NixOS vulnerability analysis and mitigation

Overview

CVE-2025-2866 is a cryptographic signature verification vulnerability discovered in LibreOffice that affects PDF signature validation. The vulnerability was disclosed on April 27, 2025, and impacts LibreOffice versions from 24.8 before 24.8.6, and from 25.2 before 25.2.2. The flaw exists in the verification code for adbe.pkcs7.sha1 signatures, which could cause invalid signatures to be accepted as valid (LibreOffice Advisory, NVD).

Technical details

The vulnerability is classified as an Improper Verification of Cryptographic Signature (CWE-347). According to the CVSS v4.0 assessment by The Document Foundation, it received a base score of 2.4 (LOW) with the vector string CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N. However, the NVD assessment indicates a CVSS 3.1 base score of 9.8 (CRITICAL) with vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H (NVD).

Impact

The vulnerability allows attackers to bypass signature verification in PDF documents, potentially leading to the acceptance of invalid signatures as valid. This could compromise the integrity and authenticity verification of signed PDF documents within LibreOffice (LibreOffice Advisory, Wiz).

Mitigation and workarounds

Users are recommended to upgrade to LibreOffice version 24.8.6 or 25.2.2 or later to address this vulnerability. The fix was developed with the assistance of Juraj Šarinay, who discovered the issue and provided the solution (LibreOffice Advisory).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management