Back Linuxsecurity Ubuntu LibreOffice Critical Denial of Service Vulnerabilities USN-8868
Running self-managed GitLab? Critical flaws could allow server code execution. Check the fixes. ×
Several security issues were fixed in LibreOffice. Software Description: - libreoffice: Office productivity suite Details: It was discovered that LibreOffice incorrectly handled WMF image imports. An attacker could possibly use this issue to cause LibreOffice to crash, resulting in a denial of service, or execute arbitrary code. (CVE-2026-63272) It was discovered that LibreOffice incorrectly handled PDF document imports. An attacker could possibly use this issue to cause LibreOffice to crash, resulting in a denial of service, or execute arbitrary code. (CVE-2026-63273, CVE-2026-63274) It was discovered that LibreOffice incorrectly handled CFF fonts embedded in documents. An attacker could possibly use this issue to cause LibreOffice to crash, resulting in a denial of service, or execute arbitrary code. (CVE-2026-63275, CVE-2026-63276) It was discovered that LibreOffice incorrectly validated package URLs. An attacker could possibly use this issue to obtain sensitive informatio... Read the Full Advisory
Several security issues were fixed in LibreOffice.
Software Description:
- libreoffice: Office productivity suite
It was discovered that LibreOffice incorrectly handled WMF image
imports. An attacker could possibly use this issue to cause LibreOffice
to crash, resulting in a denial of service, or execute arbitrary code.
It was discovered that LibreOffice incorrectly handled PDF document
imports. An attacker could possibly use this issue to cause LibreOffice
to crash, resulting in a denial of service, or execute arbitrary code.
(CVE-2026-63273, CVE-2026-63274)
It was discovered that LibreOffice incorrectly handled CFF fonts
embedded in documents. An attacker could possibly use this issue to
cause LibreOffice to crash, resulting in a denial of service, or
execute arbitrary code. (CVE-2026-63275, CVE-2026-63276)
It was discovered that LibreOffice incorrectly validated package URLs.
An attacker could possibly use this issue to obtain sensitive
The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS libreoffice 4:26.2.6.3-0ubuntu0.26.04.2 Ubuntu 24.04 LTS libreoffice 4:24.2.7-0ubuntu0.24.04.7 Ubuntu 22.04 LTS libreoffice 1:7.3.7-0ubuntu0.22.04.13 This update uses a new upstream release, which includes additional bug fixes. In general, a standard system update will make all the necessary changes.
CVE-2026-50593, CVE-2026-63272, CVE-2026-63273, CVE-2026-63274,
CVE-2026-63275, CVE-2026-63276, CVE-2026-63278, CVE-2026-63279
Ubuntu Security Notice USN-8868-1
Get the latest News and Insights
Get the latest Linux and open source security news straight to your inbox.
Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
