Heap buffer overflow in Calc formula compilation
13Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 5.4epss 0.2%
probabilidad de explotación
0.2%top 95% de las CVE
explotación observada
noninguna fuente lo reporta
LibreOffice Calc compiles cell formulas when opening a spreadsheet. A heap buffer overflow existed when compiling a very long formula made up of many opening tokens. The array that tracks nesting depth was allocated one element too small for that worst case, so such a formula wrote one element past its end. In fixed versions the array is sized to hold the largest possible nesting.
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:P
Productos afectados
The Document Foundation · LibreOfficeReferencias
https://access.redhat.com/errata/RHSA-2026:35839https://access.redhat.com/errata/RHSA-2026:36832https://access.redhat.com/errata/RHSA-2026:43423https://access.redhat.com/errata/RHSA-2026:43424https://access.redhat.com/errata/RHSA-2026:43425https://access.redhat.com/errata/RHSA-2026:43460https://access.redhat.com/errata/RHSA-2026:43461https://access.redhat.com/errata/RHSA-2026:46386https://access.redhat.com/errata/RHSA-2026:46387https://access.redhat.com/security/cve/CVE-2026-8357https://bugzilla.redhat.com/show_bug.cgi?id=2488964https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8357.json