[ubuntu/jammy-security] libreoffice 1:7.3.7-0ubuntu0.22.04.12 (Accepted)

Marc Deslauriers marc.deslauriers at canonical.com
Mon Jul 13 14:40:06 UTC 2026


libreoffice (1:7.3.7-0ubuntu0.22.04.12) jammy-security; urgency=medium

  * SECURITY UPDATE: Heap buffer overflow in DXF polyline import
    - debian/patches/CVE-2026-6039.patch: stay within max Polygon points
    - CVE-2026-6039
  * SECURITY UPDATE: Heap buffer overflow in EMF+ gradient brush import
    - debian/patches/CVE-2026-6045-0.patch: EMF+ Use variable types according to
      EMFPLUS documentation
    - debian/patches/CVE-2026-6045-1.patch: check that the file can provide the
      claimed data
    - debian/patches/CVE-2026-6045-2.patch: tidy up emfppath.cxx edge cases
    - debian/patches/CVE-2026-6045-3.patch: check that the file can provide the
      claimed data
    - CVE-2026-6045
  * SECURITY UPDATE: Stack buffer overflow in PPT presentation import
    - debian/patches/CVE-2026-8356.patch: SdrEscherImport::RecolorGraphic
      reads but doesn't use FillColors
    - CVE-2026-8356
  * SECURITY UPDATE: Heap buffer overflow in Calc formula compilation
    - debian/patches/CVE-2026-8357.patch: A formula of length L, composed
      entirely of open tokens, needs L+1 slots
    - CVE-2026-8357
  * SECURITY UPDATE: Heap buffer overflow in spreadsheet tracked-changes import
    - debian/patches/CVE-2026-8358.patch: drop malformed duplicate-id calc
      change track actions
    - CVE-2026-8358

Date: 2026-07-10 10:54:16.569473+00:00
Changed-By: Rico Tzschichholz <ricotz at web.de>
Signed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/+source/libreoffice/1:7.3.7-0ubuntu0.22.04.12
-------------- next part --------------
Sorry, changesfile not available.


More information about the jammy-changes mailing list