[Git][security-tracker-team/security-tracker][master] new libreoffice issues

Moritz Muehlenhoff (@jmm) jmm at debian.org
Tue Sep 22 22:12:44 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
8fe49e14 by Moritz Muehlenhoff at 2026-09-22T23:11:42+02:00
new libreoffice issues

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -525,19 +525,26 @@ CVE-2026-65111 (NVIDIA NeMo Speech for all platforms contains a vulnerability wh
 CVE-2026-63386 (js-toml is a TOML parser for JavaScript. Prior to 1.1.3, load() does n ...)
 	TODO: check
 CVE-2026-63279 (LibreOffice can import PICT images, which may be embedded in documents ...)
-	TODO: check
+	- libreoffice 4:26.2.5.2-1
+	NOTE: https://www.libreoffice.org/security/#cve-2026-63279
 CVE-2026-63278 (URLs could be constructed which expanded environment variable or INI f ...)
-	TODO: check
+	- libreoffice 4:26.2.5.2-1
+	NOTE: https://www.libreoffice.org/security/#cve-2026-63278
 CVE-2026-63276 (LibreOffice converts CFF fonts to Type 1 when it subsets a font, which ...)
-	TODO: check
+	- libreoffice 4:26.2.5.2-1
+	NOTE: https://www.libreoffice.org/security/#cve-2026-63276
 CVE-2026-63275 (LibreOffice can read CFF fonts, which may be embedded in documents. A  ...)
-	TODO: check
+	- libreoffice 4:26.2.5.2-1
+	NOTE: https://www.libreoffice.org/security/#cve-2026-63275
 CVE-2026-63274 (LibreOffice Draw can import PDF documents. A heap buffer overflow exis ...)
-	TODO: check
+	- libreoffice 4:26.2.5.2-1
+	NOTE: https://www.libreoffice.org/security/#cve-2026-63274
 CVE-2026-63273 (LibreOffice Draw can import PDF documents. A heap buffer overflow exis ...)
-	TODO: check
+	- libreoffice 4:26.2.5.2-1
+	NOTE: https://www.libreoffice.org/security/#cve-2026-63273
 CVE-2026-63272 (LibreOffice can import WMF graphics, which may be embedded in document ...)
-	TODO: check
+	- libreoffice 4:26.2.5.2-1
+	NOTE: https://www.libreoffice.org/security/#cve-2026-63272
 CVE-2026-57149 (plone.app.portlets.portlets provides a Plone-specific user interface f ...)
 	TODO: check
 CVE-2026-56682 (9Router is an AI router & token saver. Prior to 0.5.6, 9Router deploym ...)


=====================================
data/dsa-needed.txt
=====================================
@@ -78,6 +78,8 @@ kitty
 libheif (aron)
   Wait until new upstream release lands in sid
 --
+libreoffice
+--
 linux (carnil)
   Wait until more issues have piled up, though try to regulary rebase for point
   releases to more 6.12.y versions



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8fe49e149f20b95a9e797e219220f7139919fc36

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8fe49e149f20b95a9e797e219220f7139919fc36
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260922/30eb1467/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list