CVE-2026-6040
authorDebian LibreOffice Maintainers <debian-openoffice@lists.debian.org>
Sat, 6 Jun 2026 20:12:08 +0000 (22:12 +0200)
committerRene Engelhard <rene@debian.org>
Sat, 6 Jun 2026 20:12:08 +0000 (22:12 +0200)
commit72ad3b4ca13377a8dc91f42f0c72c18cf0fab64e
tree73a9aa02d2586eb84c1e0f83879ae7f63072f018
parentf54d65a424fe9f359ccb32bb9a47c7e57d482a1d
CVE-2026-6040

CVE-2026-6040: ODT use-after-free in lcl_InsertBlankWidthChars

oss-fuzz efforts might not have found this because the fuzzer
dictionary was based on OpenDocument-v1.3-schema.rng and the
loext:blank-width-char isn't in that schema, adding in the extra
extension schema might help for the future.

From 997ef5c01cedc4a4f8b966310d4a79906009735e Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?Caol=C3=A1n=20McNamara?= <caolan.mcnamara@collabora.com>
Date: Thu, 9 Apr 2026 17:47:09 +0100
Subject: [PATCH] process loext:blank-width-char better

Change-Id: Iea005facd85443091c5144a0a0f8f15fa995dbf3
Reviewed-on: https://gerrit.libreoffice.org/c/core/+/203576
Reviewed-by: Xisco Fauli <xiscofauli@libreoffice.org>
Tested-by: Jenkins
Signed-off-by: Xisco Fauli <xiscofauli@libreoffice.org>
Reviewed-on: https://gerrit.libreoffice.org/c/core/+/203627
Signed-off-by: Xisco Fauli <xiscofauli@libreoffice.org>
Gbp-Pq: Name CVE-2026-6040.diff
bin/oss-fuzz-setup.sh
xmloff/source/style/xmlnumfi.cxx