CVE-2026-63274: Heap buffer overflow in PDF import stream handling

Published Sep 22, 2026
·
Updated

LibreOffice Draw can import PDF documents. A heap buffer overflow existed when importing a stream object. The length of the stream was taken from the object's own dictionary and was not checked against the number of bytes actually present, so copying the stream read and wrote past the end of the buffer holding it. In fixed versions the declared length is clamped to the bytes actually read.

Affected Software

1 affected component
LibreOffice LibreOffice Draw

Event History

Sep 22, 2026
CVE Published
via MITRE·11:10 AM
Data Sourced
via MITRE·11:10 AM
DescriptionWeakness
Data Sourced
via NVD·12:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What does an attacker need to provide to trigger this issue?

The attacker needs to supply a PDF containing a stream object whose dictionary declares a length larger than the bytes actually present in the stream.

2

Which users are exposed?

Users are exposed when LibreOffice Draw imports PDF documents. The vulnerable processing occurs during handling of PDF stream objects.

3

What behavior indicates that a fix is present?

In fixed versions, the declared stream length is clamped to the number of bytes actually read before the stream is copied.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203