Home / mailings [USN-8868-1] LibreOffice vulnerabilities
Posted on 05 October 2026
Ubuntu Security==========================================================================Ubuntu Security Notice USN-8868-1
October 05, 2026
libreoffice vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 26.04 LTS
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
Summary:
Several security issues were fixed in LibreOffice.
Software Description:
- libreoffice: Office productivity suite
Details:
It was discovered that LibreOffice incorrectly handled WMF image
imports. An attacker could possibly use this issue to cause LibreOffice
to crash, resulting in a denial of service, or execute arbitrary code.
(CVE-2026-63272)
It was discovered that LibreOffice incorrectly handled PDF document
imports. An attacker could possibly use this issue to cause LibreOffice
to crash, resulting in a denial of service, or execute arbitrary code.
(CVE-2026-63273, CVE-2026-63274)
It was discovered that LibreOffice incorrectly handled CFF fonts
embedded in documents. An attacker could possibly use this issue to
cause LibreOffice to crash, resulting in a denial of service, or
execute arbitrary code. (CVE-2026-63275, CVE-2026-63276)
It was discovered that LibreOffice incorrectly validated package URLs.
An attacker could possibly use this issue to obtain sensitive
information. (CVE-2026-63278)
It was discovered that LibreOffice incorrectly handled PICT image
imports. An attacker could possibly use this issue to cause LibreOffice
to crash, resulting in a denial of service, or obtain sensitive
information. (CVE-2026-63279)
It was discovered that LibreOffice incorrectly mitigated out-of-bounds
writes via Graphite font actions. An attacker could possibly use this
issue to cause LibreOffice to crash, resulting in a denial of service,
or execute arbitrary code. (CVE-2026-50593)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 26.04 LTS
libreoffice 4:26.2.6.3-0ubuntu0.26.04.2
Ubuntu 24.04 LTS
libreoffice 4:24.2.7-0ubuntu0.24.04.7
Ubuntu 22.04 LTS
libreoffice 1:7.3.7-0ubuntu0.22.04.13
This update uses a new upstream release, which includes additional bug
fixes. In general, a standard system update will make all the necessary
changes.
References:
https://ubuntu.com/security/notices/USN-8868-1
CVE-2026-50593, CVE-2026-63272, CVE-2026-63273, CVE-2026-63274,
CVE-2026-63275, CVE-2026-63276, CVE-2026-63278, CVE-2026-63279
Package Information:
https://launchpad.net/ubuntu/+source/libreoffice/4:26.2.6.3-0ubuntu0.26.04.2
https://launchpad.net/ubuntu/+source/libreoffice/4:24.2.7-0ubuntu0.24.04.7
https://launchpad.net/ubuntu/+source/libreoffice/1:7.3.7-0ubuntu0.22.04.13
--===============4321948578272714077==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
