CVE-2026-6040 Details
Description
A heap use-after-free existed when importing the blank-width characters of an ODF number format. A position value read from the document was not checked against the length of the format-code string, so a malformed number format could be processed against memory outside that string. In fixed versions the position is bounds-checked before use.
A heap use-after-free vulnerability has been identified in LibreOffice when importing blank-width characters of an ODF number format. The issue arises because a position value read from the document was not properly checked against the length of the format-code string. This oversight allowed a malformed number format to be processed, leading to memory access outside the intended string bounds. Exploitation of this vulnerability could potentially be used to execute arbitrary code. The vulnerability is present in LibreOffice versions prior to 26.2.3 and 25.8.7.
Users can upgrade to LibreOffice versions 26.2.3, 25.8.7, or 24.2.5 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 15, 2026CISA-ADP
Assessed Jun 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-6040 | redhat-SADP | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2488966 | redhat-SADP | |
| https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6040.json | redhat-SADP | |
| https://www.libreoffice.org/about-us/security/advisories/cve-2026-6040 | [email protected] | AdvisoryBundleVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-416 | Use After Free | [email protected] |
| CWE-787 | Out-of-bounds Write | [email protected] |
| CWE-825 | Expired Pointer Dereference | redhat-SADP |
Affected Products
| Product | Versions |
|---|---|
| LibreOffice | < 26.2.3 (semver) < 25.8.7 (semver) |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 23, 2026 | CVE Modified | redhat-SADP |
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 15, 2026 | New CVE Received | [email protected] |
Volerion