{"id":"MGASA-2026-0259","summary":"Updated libreoffice packages fix security vulnerabilities","details":"The updated packages fix security vulnerabilities:\nHeap buffer overflow in DXF polyline import. (CVE-2026-6039)\nHeap use-after-free in ODF number-format blank-width parsing.\n(CVE-2026-6040)\nHeap buffer overflow in EMF+ gradient brush import. (CVE-2026-6045)\nStack buffer overflow in PPT presentation import. (CVE-2026-8356)\nHeap buffer overflow in Calc formula compilation. (CVE-2026-8357)\nHeap buffer overflow in spreadsheet tracked-changes import.\n(CVE-2026-8358)\n","modified":"2026-07-18T06:00:05.202862912Z","published":"2026-07-18T05:48:16Z","upstream":["CVE-2026-6039","CVE-2026-6040","CVE-2026-6045","CVE-2026-8356","CVE-2026-8357","CVE-2026-8358"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2026-0259.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=35709"},{"type":"WEB","url":"https://lists.debian.org/debian-security-announce/2026/msg00257.html"},{"type":"WEB","url":"https://www.libreoffice.org/security/"}],"affected":[{"package":{"name":"libreoffice","ecosystem":"Mageia:10","purl":"pkg:rpm/mageia/libreoffice?arch=source&distro=mageia-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"26.2.4.2-1.mga10"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0259.json"}},{"package":{"name":"libreoffice","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/libreoffice?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"24.2.7.2-1.5.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0259.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}