CVE-2026-8358: Heap buffer overflow in spreadsheet tracked-changes import
Last updated 4 July 2026
Other sources
LibreOffice Calc can import tracked changes from a spreadsheet document. A heap buffer overflow existed when a document reused the same change identifier for two different kinds of change. The importer then treated one change object as a different, larger type and wrote past the end of its allocation. In fixed versions records with a duplicate identifier are rejected.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/libreofficeto a version that resolves this vulnerability.Fixed in 4:7.4.7-1+deb12u14Fixed in 4:7.4.7-1+deb12u13Fixed in 4:25.2.3-2+deb13u6Fixed in 4:25.2.3-2+deb13u5Fixed in 4:26.2.4.2-2 - Upgrade
Upgrade
LibreOffice Calcto a version that resolves this vulnerability.Fixed in fixed versions records with a duplicate identifier are rejected
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8358?
CVE-2026-8358 has a medium severity rating of 5.4 according to CVSS.
How does CVE-2026-8358 affect LibreOffice Calc?
CVE-2026-8358 results in a heap buffer overflow when importing tracked changes from spreadsheet documents.
What causes CVE-2026-8358?
The vulnerability occurs when a document reuses the same change identifier for different types of changes, leading to improper memory allocation.
What versions of LibreOffice Calc are affected by CVE-2026-8358?
CVE-2026-8358 impacts specific versions of LibreOffice Calc that support importing tracked changes.
How can I mitigate the risk of CVE-2026-8358?
To mitigate CVE-2026-8358, it is recommended to update to a patched version of LibreOffice Calc as soon as it becomes available.