CVE-2026-63279
Publication date 22 September 2026
Last updated 5 October 2026
Ubuntu priority
Description
LibreOffice can import PICT images, which may be embedded in documents. An out of bounds read existed when importing an image that uses a colour palette. The palette index held in the image data was used without being checked against the number of entries the palette has, so an index past the last entry read memory outside the palette. In fixed versions the palette index is limited to the entries present.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| libreoffice | 26.04 LTS resolute |
Fixed 4:26.2.6.3-0ubuntu0.26.04.2
|
| 24.04 LTS noble |
Fixed 4:24.2.7-0ubuntu0.24.04.7
|
|
| 22.04 LTS jammy |
Fixed 1:7.3.7-0ubuntu0.22.04.13
|
|
| 20.04 LTS focal |
Needs evaluation
|
Severity score breakdown
CVSS version: CVSS v4.0
Base score
5.4 · Medium
Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:P
References
Related Ubuntu Security Notices (USN)
- USN-8868-1
- LibreOffice vulnerabilities
- 5 October 2026