LibreOffice 26.2.x Stack Buffer Overflow in CFF to Type1 Font Conversion
CVE-2026-63276 Published on September 22, 2026
Stack buffer overflow in CFF to Type 1 font conversion
LibreOffice converts CFF fonts to Type 1 when it subsets a font, which happens when a document is exported to PDF, and CFF fonts may be embedded in documents. A stack buffer overflow existed in that conversion. The converted operators were written into a fixed size buffer with no check that they still fit, so a glyph emitting many operators wrote past the end of the buffer. In fixed versions the remaining capacity is tracked and the conversion stops when it is used up.
Vulnerability Analysis
CVE-2026-63276 is exploitable with local system access. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.
Weakness Type
What is a Memory Corruption Vulnerability?
The software writes data past the end, or before the beginning, of the intended buffer. Typically, this can result in corruption of data, a crash, or code execution. The software may modify an index or perform pointer arithmetic that references a memory location that is outside of the boundaries of the buffer. A subsequent write operation then produces undefined or unexpected results.
CVE-2026-63276 has been classified to as a Memory Corruption vulnerability or weakness.
Products Associated with CVE-2026-63276
Want to know whenever a new CVE is published for Canonical Ubuntu Linux? stack.watch will email you.
Affected Versions
The Document Foundation LibreOffice:- Version 26.2 and below < 26.2.5 is affected.