Bug 2537936 (CVE-2026-63274) - CVE-2026-63274 libreoffice: heap buffer overflow in PDF import stream handling
Summary: CVE-2026-63274 libreoffice: heap buffer overflow in PDF import stream handling
Keywords:
Status: NEW
Alias: CVE-2026-63274
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2540063
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-22 16:14 UTC by OSIDB Bzimport
Modified: 2026-09-24 13:37 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-22 16:14:12 UTC
LibreOffice Draw can import PDF documents. A heap buffer overflow existed when importing a stream object. The length of the stream was taken from the object's own dictionary and was not checked against the number of bytes actually present, so copying the stream read and wrote past the end of the buffer holding it. In fixed versions the declared length is clamped to the bytes actually read.


Note You need to log in before you can comment on or make changes to this bug.