{"id":"CVE-2026-6045","title":"Heap buffer overflow in EMF+ gradient brush import","summary":"LibreOffice can import EMF+ graphics, which may be embedded in documents. A heap buffer overflow existed when importing an EMF+ gradient brush. The number of gradient blend points was read from the file and used to compute an allocation …","severity":"medium","cvss":5.4,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:P","cvssSource":"cna","cwe":["CWE-787","CWE-190"],"vendor":"The Document Foundation","product":"LibreOffice","affected":["LibreOffice >= 25.8 < < 25.8.7","LibreOffice >= 26.2 < < 26.2.3"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-06-15T18:12:50.303654Z"},"published":"2026-06-15","updated":"2026-09-28","sourceUpdated":"2026-09-28T14:22:54.255Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-6045","references":[{"url":"https://www.libreoffice.org/about-us/security/advisories/cve-2026-6045"}],"tags":["cve.org"],"epss":0.00167,"epssPercentile":0.05353,"ingestedAt":"2026-09-28T15:13:31.605Z","slug":"CVE-2026-6045","body":"## Overview\n\nLibreOffice can import EMF+ graphics, which may be embedded in documents. A heap buffer overflow existed when importing an EMF+ gradient brush. The number of gradient blend points was read from the file and used to compute an allocation size, but that multiplication could overflow, so a small buffer was allocated and then filled as if it were large, writing past its end. In fixed versions the blend-point count is checked against the data actually available before allocating.\n\n## Affected\n\n- `LibreOffice >= 25.8 < < 25.8.7`\n- `LibreOffice >= 26.2 < < 26.2.3`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":29.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}