CVE-2026-63275EPSS p5.4%
CVE-2026-63275CVE-2026-63275
Description
LibreOffice can read CFF fonts, which may be embedded in documents. A stack buffer overflow existed when reading the hints of a glyph. The number of hints was checked against the wrong bound, so a glyph declaring more hints than the array can hold wrote past its end. In fixed versions the hint count is checked against the capacity the array really has.
Scoring
| EPSS | 0.17% probability of exploitation · percentile 5.4% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-22 |