Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 431
Alerts This Week
Warning Icon 1 431

SUSE LibreOffice Important Denial of Service Updates 2026-3140-1

suse
Calendar Grey July 21, 2026
Scroller Suse
Important SUSE LibreOffice update addresses nine security issues and introduces new features for user safety.
SUSE released a security update for LibreOffice, fixing nine vulnerabilities and updating to version 26.2.5.1, enhancing product security and stability across supported openSUSE an...

Summary

## This update for libreoffice fixes the following issues: Update to LibreOffice 26.2.5.1. Security issues fixed: * CVE-2026-4430: out-of-bounds write via crafted OOXML documents with mismatched encryption salt parameters (bsc#1264357). * CVE-2026-6039: denial of service via specially crafted DXF polyline import (bsc#1268494). * CVE-2026-6040: heap use-after-free when importing the blank-width characters of an ODF number format (bsc#1268527). * CVE-2026-6045: heap buffer overflow via crafted EMF+ graphics import (bsc#1268497). * CVE-2026-6047: denial of service via heap buffer overflow in OOXML document processing (bsc#1268504). * CVE-2026-8356: denial of service via a specially crafted PPT file (bsc#1268522). * CVE-2026-8357: heap buffer overflow in Calc formula compilation (bsc#1268528).

References

* bsc#1264357

* bsc#1267735

* bsc#1268494

* bsc#1268497

* bsc#1268504

* bsc#1268522

* bsc#1268527

* bsc#1268528

* bsc#1268529

* jsc#PED-16098

Cross-

* CVE-2026-4430

* CVE-2026-50593

* CVE-2026-6039

* CVE-2026-6040

* CVE-2026-6045

* CVE-2026-6047

* CVE-2026-8356

* CVE-2026-8357

* CVE-2026-8358

CVSS scores:

* CVE-2026-4430 ( SUSE ): 7.3

CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

* CVE-2026-4430 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

* CVE-2026-4430 ( NVD ): 5.4

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

* CVE-2026-4430 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:3140-1
Release Date: 2026-07-20T18:01:17Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.