Ubuntu Security Notices guidance
Vendor revision: Oct 5, 2026(CVE-2026-63279) It was discovered that LibreOffice incorrectly mitigated out-of-bounds writes via Graphite font actions.
Vulnerability intelligence
CVE-2026-50593 and is rated High severity with a CVSS score of 7.3. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
(CVE-2026-63279) It was discovered that LibreOffice incorrectly mitigated out-of-bounds writes via Graphite font actions.
Graphite before 1.3.15 has an integer underflow and resultant out-of-bounds write via Graphite actions, because slotat does not ensure that an offset is within the allowed slot-map range.
Source: NVD