CVE-2026-6040
HIGHHeap use-after-free in ODF number-format blank-width parsing
Title source: cnaDescription
A heap use-after-free existed when importing the blank-width characters of an ODF number format. A position value read from the document was not checked against the length of the format-code string, so a malformed number format could be processed against memory outside that string. In fixed versions the position is bounds-checked before use.
References (4)
Core 4
Core References
Vendor Advisory
https://access.redhat.com/security/cve/CVE-2026-6040
Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2488966
Scores
CVSS v3
7.3
EPSS
0.0011
EPSS Percentile
1.7%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-416
CWE-787
CWE-825
Status
published
Products (2)
The Document Foundation/LibreOffice
25.8 - < 25.8.7
The Document Foundation/LibreOffice
26.2 - < 26.2.3
Published
Jun 15, 2026
Tracked Since
Jun 15, 2026