
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-63276 is a stack buffer overflow vulnerability in LibreOffice's CFF (Compact Font Format) to Type 1 font conversion process, triggered during PDF export. When a document containing an embedded CFF font is exported to PDF, LibreOffice subsets the font by converting CFF operators into a fixed-size buffer without checking remaining capacity; a glyph emitting many operators can write past the end of the buffer, causing memory corruption. The vulnerability affects LibreOffice versions in the 26.2 series prior to 26.2.5, developed by The Document Foundation. It carries a CVSS v4.0 base score of 5.4 (Medium) with a proof-of-concept exploit maturity rating (GitHub Advisory, LibreOffice Advisory).
The root cause is an out-of-bounds write (CWE-787) in LibreOffice's CFF-to-Type-1 font conversion routine invoked during PDF export. Converted font operators are written sequentially into a fixed-size stack buffer with no bounds checking; when a specially crafted glyph emits a sufficiently large number of operators, the write operation overflows the buffer boundary, corrupting adjacent stack memory. Exploitation requires local access and passive user interaction — specifically, a user must open and export a document containing a maliciously crafted embedded CFF font to PDF. In fixed versions, the remaining buffer capacity is tracked and the conversion halts before overflow occurs (GitHub Advisory, LibreOffice Advisory).
Successful exploitation can result in arbitrary code execution with the privileges of the LibreOffice process, as well as application crashes (high availability impact). The vulnerability also carries low confidentiality and integrity impacts to the vulnerable system, as memory corruption may expose or corrupt in-process data. Because exploitation is local and requires user interaction (opening and exporting a crafted document), the blast radius is limited to the affected user's session and does not directly enable lateral movement or network-level compromise (GitHub Advisory).
The CVE status is listed as "Deferred" and the CVSS v4.0 exploit maturity is rated "Proof of Concept," though no public PoC code or active in-the-wild exploitation has been confirmed at this time (GitHub Advisory). The EPSS score is 0.0, indicating a very low current probability of exploitation in the wild, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. NVD SSVC assessment also confirms no known exploitation and classifies the vulnerability as non-automatable (LibreOffice Advisory).
soffice, soffice.bin) crashing unexpectedly or generating core dumps during PDF export operations involving documents with embedded fonts.core, core.soffice.bin) in the working directory or system crash dump location following a PDF export action; presence of documents with unusual or oversized embedded CFF font data.The vendor has released a patch in LibreOffice version 26.2.5, which tracks remaining buffer capacity during CFF-to-Type-1 conversion and halts the process before overflow occurs; users should upgrade to 26.2.5 or later immediately (LibreOffice Advisory). As a temporary workaround until patching is possible, organizations should restrict PDF export functionality for documents from untrusted sources and avoid opening documents with embedded CFF fonts from unknown origins. Limiting document handling to trusted sources and disabling or restricting the PDF export feature in high-risk environments can reduce exposure.
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."