CVE-2026-6045
authorDebian LibreOffice Maintainers <debian-openoffice@lists.debian.org>
Mon, 25 May 2026 11:04:01 +0000 (13:04 +0200)
committerRene Engelhard <rene@debian.org>
Mon, 25 May 2026 11:04:01 +0000 (13:04 +0200)
commit2d46fba867b534ebae5a7a660fc393872b67fdab
treeaa04724b69d3f9c4adf0fd96580fe702d5536634
parentd9b153ff745dc03af90865aed76b0bac45c056b4
CVE-2026-6045

CVE-2026-6045 EMF+ Heap-buffer-overflow in EMFPBrush::Read

CVE-2026-6045 EMF+ Heap-buffer-overflow in EMFPBrush::Read
A nested format problem tucked away in the rendering path, probably
need to add something dedicated to the simpler fuzzer to force that
render path to be exercised.

From 279c7ea61829efe5cabc5832d06e1833ad28379f Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?Caol=C3=A1n=20McNamara?= <caolan.mcnamara@collabora.com>
Date: Thu, 9 Apr 2026 20:00:38 +0100
Subject: [PATCH] check that the file can provide the claimed data

and make sure we initialize these locals

Change-Id: Ifa899e36f678216574364e5206037ab57b2d19d9
Reviewed-on: https://gerrit.libreoffice.org/c/core/+/203577
Tested-by: Jenkins
Reviewed-by: Xisco Fauli <xiscofauli@libreoffice.org>
Signed-off-by: Xisco Fauli <xiscofauli@libreoffice.org>
Reviewed-on: https://gerrit.libreoffice.org/c/core/+/203628
Signed-off-by: Xisco Fauli <xiscofauli@libreoffice.org>
Gbp-Pq: Name CVE-2026-6045.diff
drawinglayer/source/tools/emfpbrush.cxx
drawinglayer/source/tools/emfppen.cxx