CVE-2026-63276: 
LibreOffice vulnerability analysis and mitigation

Overview

CVE-2026-63276 is a stack buffer overflow vulnerability in LibreOffice's CFF (Compact Font Format) to Type 1 font conversion process, triggered during PDF export. When a document containing an embedded CFF font is exported to PDF, LibreOffice subsets the font by converting CFF operators into a fixed-size buffer without checking remaining capacity; a glyph emitting many operators can write past the end of the buffer, causing memory corruption. The vulnerability affects LibreOffice versions in the 26.2 series prior to 26.2.5, developed by The Document Foundation. It carries a CVSS v4.0 base score of 5.4 (Medium) with a proof-of-concept exploit maturity rating (GitHub Advisory, LibreOffice Advisory).

Technical details

The root cause is an out-of-bounds write (CWE-787) in LibreOffice's CFF-to-Type-1 font conversion routine invoked during PDF export. Converted font operators are written sequentially into a fixed-size stack buffer with no bounds checking; when a specially crafted glyph emits a sufficiently large number of operators, the write operation overflows the buffer boundary, corrupting adjacent stack memory. Exploitation requires local access and passive user interaction — specifically, a user must open and export a document containing a maliciously crafted embedded CFF font to PDF. In fixed versions, the remaining buffer capacity is tracked and the conversion halts before overflow occurs (GitHub Advisory, LibreOffice Advisory).

Impact

Successful exploitation can result in arbitrary code execution with the privileges of the LibreOffice process, as well as application crashes (high availability impact). The vulnerability also carries low confidentiality and integrity impacts to the vulnerable system, as memory corruption may expose or corrupt in-process data. Because exploitation is local and requires user interaction (opening and exporting a crafted document), the blast radius is limited to the affected user's session and does not directly enable lateral movement or network-level compromise (GitHub Advisory).

Exploitability

The CVE status is listed as "Deferred" and the CVSS v4.0 exploit maturity is rated "Proof of Concept," though no public PoC code or active in-the-wild exploitation has been confirmed at this time (GitHub Advisory). The EPSS score is 0.0, indicating a very low current probability of exploitation in the wild, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. NVD SSVC assessment also confirms no known exploitation and classifies the vulnerability as non-automatable (LibreOffice Advisory).

Exploitation steps

  1. Craft a malicious document: Create or modify a document (e.g., ODT or DOCX) that embeds a specially crafted CFF font containing a glyph designed to emit an abnormally large number of Type 1 operators during font subsetting.
  2. Deliver the document: Distribute the crafted document to a target user via email, file share, or other social engineering means, relying on passive user interaction to open it in LibreOffice.
  3. Trigger PDF export: Induce the target user to export the document to PDF (e.g., via File > Export as PDF), which initiates the CFF-to-Type-1 font conversion and font subsetting process.
  4. Overflow the stack buffer: During conversion, the malicious glyph's excessive operator output writes past the end of the fixed-size stack buffer, corrupting adjacent stack memory.
  5. Achieve code execution or crash: Depending on the crafted payload and memory layout, the attacker may achieve arbitrary code execution with the privileges of the LibreOffice process, or cause a denial-of-service crash (GitHub Advisory, LibreOffice Advisory).

Indicators of compromise

  • Process: LibreOffice process (soffice, soffice.bin) crashing unexpectedly or generating core dumps during PDF export operations involving documents with embedded fonts.
  • File System: Unexpected core dump files (e.g., core, core.soffice.bin) in the working directory or system crash dump location following a PDF export action; presence of documents with unusual or oversized embedded CFF font data.
  • Logs: Application crash logs or OS-level segmentation fault reports referencing LibreOffice during PDF export; system logs showing abnormal termination of the LibreOffice process.
  • Behavioral: Unusual child processes spawned by LibreOffice following a PDF export action, which may indicate successful code execution rather than a simple crash.

Mitigation and workarounds

The vendor has released a patch in LibreOffice version 26.2.5, which tracks remaining buffer capacity during CFF-to-Type-1 conversion and halts the process before overflow occurs; users should upgrade to 26.2.5 or later immediately (LibreOffice Advisory). As a temporary workaround until patching is possible, organizations should restrict PDF export functionality for documents from untrusted sources and avoid opening documents with embedded CFF fonts from unknown origins. Limiting document handling to trusted sources and disabling or restricting the PDF export feature in high-risk environments can reduce exposure.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

libreoffice

Affected

sid

libreoffice: 4:26.2.5.2-1

Fixed

trixie

libreoffice

Affected

Ubuntu

Unknown

devel

libreoffice

Unknown

focal (esm-infra)

libreoffice

Unknown

jammy

libreoffice

Unknown

noble

libreoffice

Unknown

resolute

libreoffice

Unknown

RHEL / CentOS

Affected

RHEL 8

Not Affected

RHEL 9

Not Affected

Source: This report was generated using AI

Related LibreOffice vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-63278MEDIUM6.7
  • LibreOffice logoLibreOffice
  • cpe:2.3:a:libreoffice:libreoffice
NoYesSep 22, 2026
CVE-2026-63279MEDIUM5.4
  • LibreOffice logoLibreOffice
  • libreoffice
NoYesSep 22, 2026
CVE-2026-63276MEDIUM5.4
  • LibreOffice logoLibreOffice
  • cpe:2.3:a:libreoffice:libreoffice
NoYesSep 22, 2026
CVE-2026-63275MEDIUM5.4
  • LibreOffice logoLibreOffice
  • libreoffice
NoYesSep 22, 2026
CVE-2026-63274MEDIUM5.4
  • LibreOffice logoLibreOffice
  • libreoffice
NoYesSep 22, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management