CVE-2026-6045
authorDebian LibreOffice Maintainers <debian-openoffice@lists.debian.org>
Sat, 6 Jun 2026 20:12:08 +0000 (22:12 +0200)
committerRene Engelhard <rene@debian.org>
Sat, 6 Jun 2026 20:12:08 +0000 (22:12 +0200)
commit1bc7cdb0fa905c70101a65b7035e07e2086b9b1a
tree8617108a51654427dfbfe9a0f8cd79da77184f2f
parent72ad3b4ca13377a8dc91f42f0c72c18cf0fab64e
CVE-2026-6045

CVE-2026-6045 EMF+ Heap-buffer-overflow in EMFPBrush::Read

CVE-2026-6045 EMF+ Heap-buffer-overflow in EMFPBrush::Read
A nested format problem tucked away in the rendering path, probably
need to add something dedicated to the simpler fuzzer to force that
render path to be exercised.

From 279c7ea61829efe5cabc5832d06e1833ad28379f Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?Caol=C3=A1n=20McNamara?= <caolan.mcnamara@collabora.com>
Date: Thu, 9 Apr 2026 20:00:38 +0100
Subject: [PATCH] check that the file can provide the claimed data

and make sure we initialize these locals

Change-Id: Ifa899e36f678216574364e5206037ab57b2d19d9
Reviewed-on: https://gerrit.libreoffice.org/c/core/+/203577
Tested-by: Jenkins
Reviewed-by: Xisco Fauli <xiscofauli@libreoffice.org>
Signed-off-by: Xisco Fauli <xiscofauli@libreoffice.org>
Reviewed-on: https://gerrit.libreoffice.org/c/core/+/203628
Signed-off-by: Xisco Fauli <xiscofauli@libreoffice.org>
Gbp-Pq: Name CVE-2026-6045.diff
drawinglayer/source/tools/emfpbrush.cxx
drawinglayer/source/tools/emfppen.cxx