CVE-2026-6039
authorDebian LibreOffice Maintainers <debian-openoffice@lists.debian.org>
Mon, 25 May 2026 11:04:01 +0000 (13:04 +0200)
committerRene Engelhard <rene@debian.org>
Mon, 25 May 2026 11:04:01 +0000 (13:04 +0200)
commitd9b153ff745dc03af90865aed76b0bac45c056b4
treec195cf42da57b1af8ecf956b53aadf1846220c44
parent0d5c05e173d9b6ee8c0cc95c4ba14cb65c0923f0
CVE-2026-6039

CVE-2026-6039: DXF heap-buffer-overflow in DrawLWPolyLineEntity

It looks like our oss-fuzz efforts didn't find this because we capped
the dxffuzzer.options size at 64KB which is too small to capture this
issue.

From cf825c7608ded2cb1b7c846bde15d0ebcf6a5c44 Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?Caol=C3=A1n=20McNamara?= <caolan.mcnamara@collabora.com>
Date: Thu, 9 Apr 2026 17:23:39 +0100
Subject: [PATCH] stay within max Polygon points

Change-Id: I02e34bb413e6332d8c5683504a63a591a33d7730
Reviewed-on: https://gerrit.libreoffice.org/c/core/+/203575
Reviewed-by: Xisco Fauli <xiscofauli@libreoffice.org>
Tested-by: Jenkins
Signed-off-by: Xisco Fauli <xiscofauli@libreoffice.org>
Reviewed-on: https://gerrit.libreoffice.org/c/core/+/203626
Signed-off-by: Xisco Fauli <xiscofauli@libreoffice.org>
Gbp-Pq: Name CVE-2026-6039.diff
vcl/source/filter/idxf/dxf2mtf.cxx
vcl/workben/dxffuzzer.options