Skip to content
Ubuntu LibreOffice Critical Denial of Service Vulnerabilities USN-8868

Ubuntu LibreOffice Critical Denial of Service Vulnerabilities USN-8868

Linuxsecurity •LinuxSecurity Advisories • October 5, 2026

Running self-managed GitLab? Critical flaws could allow server code execution. Check the fixes. ×

Several security issues were fixed in LibreOffice. Software Description: - libreoffice: Office productivity suite Details: It was discovered that LibreOffice incorrectly handled WMF image imports. An attacker could possibly use this issue to cause LibreOffice to crash, resulting in a denial of service, or execute arbitrary code. (CVE-2026-63272) It was discovered that LibreOffice incorrectly handled PDF document imports. An attacker could possibly use this issue to cause LibreOffice to crash, resulting in a denial of service, or execute arbitrary code. (CVE-2026-63273, CVE-2026-63274) It was discovered that LibreOffice incorrectly handled CFF fonts embedded in documents. An attacker could possibly use this issue to cause LibreOffice to crash, resulting in a denial of service, or execute arbitrary code. (CVE-2026-63275, CVE-2026-63276) It was discovered that LibreOffice incorrectly validated package URLs. An attacker could possibly use this issue to obtain sensitive informatio... Read the Full Advisory

Several security issues were fixed in LibreOffice.

Software Description:

- libreoffice: Office productivity suite

It was discovered that LibreOffice incorrectly handled WMF image

imports. An attacker could possibly use this issue to cause LibreOffice

to crash, resulting in a denial of service, or execute arbitrary code.

It was discovered that LibreOffice incorrectly handled PDF document

imports. An attacker could possibly use this issue to cause LibreOffice

to crash, resulting in a denial of service, or execute arbitrary code.

(CVE-2026-63273, CVE-2026-63274)

It was discovered that LibreOffice incorrectly handled CFF fonts

embedded in documents. An attacker could possibly use this issue to

cause LibreOffice to crash, resulting in a denial of service, or

execute arbitrary code. (CVE-2026-63275, CVE-2026-63276)

It was discovered that LibreOffice incorrectly validated package URLs.

An attacker could possibly use this issue to obtain sensitive

The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS libreoffice 4:26.2.6.3-0ubuntu0.26.04.2 Ubuntu 24.04 LTS libreoffice 4:24.2.7-0ubuntu0.24.04.7 Ubuntu 22.04 LTS libreoffice 1:7.3.7-0ubuntu0.22.04.13 This update uses a new upstream release, which includes additional bug fixes. In general, a standard system update will make all the necessary changes.

CVE-2026-50593, CVE-2026-63272, CVE-2026-63273, CVE-2026-63274,

CVE-2026-63275, CVE-2026-63276, CVE-2026-63278, CVE-2026-63279

Ubuntu Security Notice USN-8868-1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases