NONE · 0

CVE-2026-6047

LibreOffice can import documents in the OOXML format (DOCX). A heap buffer overflow existed when replaying deferred parser events for a text box element. A handler object was assumed to be of one type...

Vulnerability Description

LibreOffice can import documents in the OOXML format (DOCX). A heap buffer overflow existed when replaying deferred parser events for a text box element. A handler object was assumed to be of one type and written to at that type's field layout, but it could be a smaller object, so the write landed past the end of the allocation. In fixed versions the type is checked before the write.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-6047?

CVE-2026-6047 is a documented vulnerability. LibreOffice can import documents in the OOXML format (DOCX). A heap buffer overflow existed when replaying deferred parser events for a text box element. A handler object was assumed to be of one type...

How severe is CVE-2026-6047?

CVSS scoring is not yet available for CVE-2026-6047. Check NVD for updates.

Is there a patch for CVE-2026-6047?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.