CVE-2018-10119: Use After Free
Last updated 25 August 2025
Other sources
LibreOffice before versions 5.4.5.1 and 6.0.1.1 is vulnerable to an integer overflow resulting in a write to recently freed data in the StgSmallStrm class from sot/source/sdstor/stgstrms.cxx. An attacker could exploit this to cause a denial of service or other unspecified impact via a crafted document.
External Reference:
https://www.libreoffice.org/about-us/security/advisories/cve-2018-10119/
Additional Reference:
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=5747
Upstream Patches:
https://gerrit.libreoffice.org/gitweb?p=core.git;a=commit;h=fdd41c995d1f719e92c6f083e780226114762f05 https://gerrit.libreoffice.org/#/c/48751/ https://gerrit.libreoffice.org/#/c/48756/ https://gerrit.libreoffice.org/#/c/48757/ https://gerrit.libreoffice.org/#/c/48758/
— Red Hat
sot/source/sdstor/stgstrms.cxx in LibreOffice before 5.4.5.1 and 6.x before 6.0.1.1 uses an incorrect integer data type in the StgSmallStrm class, which allows remote attackers to cause a denial of service (use-after-free with write access) or possibly have unspecified other impact via a crafted document that uses the structured storage ole2 wrapper file format.
— Launchpad
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-10119?
CVE-2018-10119 is a vulnerability in LibreOffice that allows remote attackers to cause a denial of service or potentially have other impacts.
How does CVE-2018-10119 affect LibreOffice?
CVE-2018-10119 affects versions of LibreOffice before 5.4.5.1 and 6.x before 6.0.1.1.
What is the severity of CVE-2018-10119?
CVE-2018-10119 has a severity rating of 7.8 (high).
How can I fix CVE-2018-10119?
To fix CVE-2018-10119, you should update your LibreOffice installation to version 5.4.5.1 or higher for versions before 6.0.1.1, and version 6.0.1.1 or higher for versions in the 6.x range.
Where can I find more information about CVE-2018-10119?
You can find more information about CVE-2018-10119 in the references provided: [RHSA-2018:3054](https://access.redhat.com/errata/RHSA-2018:3054), [oss-fuzz issue](https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=5747), [LibreOffice Gerrit change](https://gerrit.libreoffice.org/#/c/48751/).