CVE-2026-6040
CVE-2026-6040: ODT use-after-free in lcl_InsertBlankWidthChars
oss-fuzz efforts might not have found this because the fuzzer
dictionary was based on OpenDocument-v1.3-schema.rng and the
loext:blank-width-char isn't in that schema, adding in the extra
extension schema might help for the future.
From
997ef5c01cedc4a4f8b966310d4a79906009735e Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?Caol=C3=A1n=20McNamara?= <caolan.mcnamara@collabora.com>
Date: Thu, 9 Apr 2026 17:47:09 +0100
Subject: [PATCH] process loext:blank-width-char better
Change-Id: Iea005facd85443091c5144a0a0f8f15fa995dbf3
Reviewed-on: https://gerrit.libreoffice.org/c/core/+/203576
Reviewed-by: Xisco Fauli <xiscofauli@libreoffice.org>
Tested-by: Jenkins
Signed-off-by: Xisco Fauli <xiscofauli@libreoffice.org>
Reviewed-on: https://gerrit.libreoffice.org/c/core/+/203627
Signed-off-by: Xisco Fauli <xiscofauli@libreoffice.org>
Gbp-Pq: Name CVE-2026-6040.diff