Bug 2541403 - CVE-2026-97222 gnumeric: gnumeric: heap use-after-free when opening a malformed workbook [fedora-all]
Summary: CVE-2026-97222 gnumeric: gnumeric: heap use-after-free when opening a malform...
Keywords:
Status: NEW
Alias: None
Product: Fedora
Classification: Fedora
Component: gnumeric
Version: rawhide
Hardware: Unspecified
OS: Unspecified
medium
medium
Target Milestone: ---
Assignee: Huzaifa S. Sidhpurwala
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: {"flaws": ["995c7c47-5b53-4dc1-92e3-f...
Depends On:
Blocks: CVE-2026-97222
TreeView+ depends on / blocked
 
Reported: 2026-09-25 13:07 UTC by Vladimir Vasilev
Modified: 2026-09-25 13:07 UTC (History)
3 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Vladimir Vasilev 2026-09-25 13:07:38 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

A heap use-after-free flaw was found in Gnumeric's workbook XML parser. A malformed SheetObjectComponent element can cause the parser to release a sheet-object component and later pass the freed object to sheet_object_component_set_component(). When a user opens a crafted Gnumeric workbook, the stale object is dereferenced during XML parsing, causing Gnumeric to crash. The issue was reproduced in the 1.12.61 release and an AddressSanitizer-instrumented development build; it was also present in source reported as version 1.11.0 and later. The available proof of concept demonstrates a denial of service only. No code execution, information disclosure, or data-integrity impact has been demonstrated. A patch was available, but no fixed release had been identified at the time of reporting.


Note You need to log in before you can comment on or make changes to this bug.