This bug was fixed in the package libreoffice -
4:26.2.6.3-0ubuntu0.26.04.2
---------------
libreoffice (4:26.2.6.3-0ubuntu0.26.04.2) resolute-security; urgency=medium
* No-change rebuild in the -security pocket.
* SECURITY UPDATE: Heap buffer overflow in WMF text record import
- CVE-2026-63272
* SECURITY UPDATE: Heap buffer overflow in PDF import encryption handling
- CVE-2026-63273
* SECURITY UPDATE: Heap buffer overflow in PDF import stream handling
- CVE-2026-63274
* SECURITY UPDATE: Stack buffer overflow in CFF font hint handling
- CVE-2026-63275
* SECURITY UPDATE: Stack buffer overflow in CFF to Type 1 font conversion
- CVE-2026-63276
* SECURITY UPDATE: Package URLs can be used to exfiltrate arbitrary INI
file values and environment variables
- CVE-2026-63278
* SECURITY UPDATE: Out of bounds read in PICT image import
- CVE-2026-63279
-- Rico Tzschichholz <[email protected]> Mon, 28 Sep 2026 10:35:32
+0200
** Changed in: libreoffice (Ubuntu Resolute)
Status: Fix Committed => Fix Released
** CVE added: https://cve.org/CVERecord?id=CVE-2026-63272
** CVE added: https://cve.org/CVERecord?id=CVE-2026-63273
** CVE added: https://cve.org/CVERecord?id=CVE-2026-63274
** CVE added: https://cve.org/CVERecord?id=CVE-2026-63275
** CVE added: https://cve.org/CVERecord?id=CVE-2026-63276
** CVE added: https://cve.org/CVERecord?id=CVE-2026-63278
** CVE added: https://cve.org/CVERecord?id=CVE-2026-63279
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2166709
Title:
[SRU] libreoffice 26.2.6 for resolute
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libreoffice/+bug/2166709/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs