gpp_maybe Security update for libreoffice
SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3140


This update for libreoffice fixes the following issues: Update to LibreOffice 26.2.5.1. Security issues fixed: - CVE-2026-4430: out-of-bounds write via crafted OOXML documents with mismatched encryption salt parameters (bsc#1264357). - CVE-2026-6039: denial of service via specially crafted DXF polyline import (bsc#1268494). - CVE-2026-6040: heap use-after-free when importing the blank-width characters of an ODF number format (bsc#1268527). - CVE-2026-6045: heap buffer overflow via crafted EMF+ graphics import (bsc#1268497). - CVE-2026-6047: denial of service via heap buffer overflow in OOXML document processing (bsc#1268504). - CVE-2026-8356: denial of service via a specially crafted PPT file (bsc#1268522). - CVE-2026-8357: heap buffer overflow in Calc formula compilation (bsc#1268528). - CVE-2026-8358: heap buffer overflow in spreadsheet tracked-changes import (bsc#1268529). - CVE-2026-50593: graphite2: out-of-bounds write via Graphite actions (bsc#1267735). Other updates and bugfixes: - Update to LibreOffice 26.2.5.1. - Update bundled dependencies: * `fontconfig` 2.17.1 -> 2.18.0 * `graphite2-minimal` 1.3.14 -> 1.3.15 * `libcmis` 0.6.2 -> 0.6.3 * `libgpg-error` 1.59 -> 1.61 * `lxml` 6.1.0 -> 6.1.1 * `md4c` 0.5.2 -> 0.5.3 * `poppler` 26.04.0 -> 26.06.0 * `sqlite-amalgamation` 3530000 -> 3530100 * `xmlsec1` 1.3.9 -> 1.3.11 - Update to LibreOffice 26.2.3.2 (PED-16098). - Upgraded dependencies: * `boost`: 1_88_0 -> 1_89_0 * `freetype`: 2.14.1 -> 2.14.3 * `harfbuzz`: 12.3.0 -> 12.3.2 * `icu4c`: 77_1 -> 78.3 * `libgpg-error`: 1.56 -> 1.59 * `liborcus`: 0.20.1 -> 0.21.0 * `pdfium`: 7012 -> 7471 * `poppler`: 25.12.0 -> 26.04.0 * `skia`: m136 -> m142 - New bundled sources: * `afdko` 4.0.3 * `antlr4-cpp-runtime` 4.13.2 * `fast_float` 8.2.2 * `libffi` 3.5.2 * `lxml` 6.1.0 * `md4c` 0.5.2 * `meson` 1.8.3 * `Python` 3.12.13 * `sqlite` 3530000 * `xmlsec1` 1.3.9 * `xz` 5.8.3 - Add `patch`, required to build the bundled Python on all architectures. - Bundling a specific Python is now required as the one we ship (3.6) is too old to build `harfbuzz`.


cloud_download Downloads

SUSE Package Hub 15.7 aarch64
SUSE Package Hub 15.7 ppc64le
SUSE Package Hub 15.7 x86_64