Home
MEDIUM: 5.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:PDefault status
unaffected
26.2 (26 series) before 26.2.3
affected
25.8 (25 series) before 25.8.7
affected
Description
Out-of-bounds write vulnerability in The Document Foundation LibreOffice via crafted OOXML documents with mismatched encryption salt parameters. This issue affects LibreOffice: from 26.2 before 26.2.3, from 25.8 before 25.8.7.
Problem types
Product status
26.2 (26 series) before 26.2.3
25.8 (25 series) before 25.8.7
Credits
Duc Anh Nguyen (@Danzation)
Caolán McNamara <caolan.mcnamara@collabora.com>
References
www.libreoffice.org/...-us/security/advisories/cve-2026-4430