Opened 5 months ago

Closed 3 months ago

#23238 closed enhancement (fixed)

libreoffice-26.2.4.2

Reported by: Bruce Dubbs Owned by: SecurityAdvisory
Priority: elevated Milestone: 13.1
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New point version.

Attachments (1)

libreoffice-26.2.4.2-poppler_26.06-1.patch​ (2.7 KB ) - added by martyj19 4 months ago.
Adjustment for poppler 26.06

Download all attachments as: .zip

Change History (13)

comment:1 by martyj19, 5 months ago

Poppler adjustments all upstream.

comment:2 by Bruce Dubbs, 5 months ago

Owner: changed from blfs-book to Bruce Dubbs
Status: new → assigned

comment:3 by Bruce Dubbs, 5 months ago

Owner: changed from Bruce Dubbs to Douglas R. Reno
Status: assigned → new

comment:4 by Douglas R. Reno, 4 months ago

Status: new → assigned

comment:5 by Joe Locash, 4 months ago

Summary: libreoffice-26.2.3.2 → libreoffice-26.2.4.1

Now at 26.2.4.1.

comment:6 by martyj19, 4 months ago

26.2.4.1 is a release candidate. Normally the release would progress to 26.2.4.2 and then be announced on libreoffice.org. The .0 releases usually progress to .0.3 with an extra release candidate.

https://wiki.documentfoundation.org/ReleasePlan/26.2

There have been times when a .1 release is announced as a critical hotfix but you can always tell by looking at the Release Plan page.

comment:7 by Douglas R. Reno, 4 months ago

Priority: normal → elevated

There should be a new version tomorrow.

In the meantime, I must report a security issue:

CVE-2026-4430 Heap Buffer Overflow in AgileEngine

Announced: May 06, 2026

Fixed in: LibreOffice 26.2.3 and LibreOffice 25.8.7

Description:

Out-of-bounds write vulnerability in The Document Foundation LibreOffice via crafted 
OOXML documents with mismatched encryption salt parameters.

This issue affects LibreOffice: from 26.2 before 26.2.3, from 25.8 before 25.8.7.

Credits:

Thanks to Duc Anh Nguyen (@Danzation) for finding and reporting this issue.

Thanks to Caolán McNamara of Collabora Productivity for providing a fix.

References:

CVE-2026-4430

This is rated as Medium, so to Elevated it goes

by martyj19, 4 months ago

Adjustment for poppler 26.06

comment:8 by martyj19, 4 months ago

Summary: libreoffice-26.2.4.1 → libreoffice-26.2.4.2

26.2.4 now uploaded and announced. Poppler 26.06 adjustment required.

Last edited 4 months ago by martyj19 (previous) (diff)

comment:9 by Douglas R. Reno, 4 months ago

Owner: changed from Douglas R. Reno to blfs-book
Status: assigned → new

I'm going to reassign these to the book for now so whoever wants to do them can do them.

In the meantime I will continue working on rivendell, but I do not want to continue holding the project back on important issues.

comment:10 by pierre, 4 months ago

Owner: changed from blfs-book to pierre
Status: new → assigned

comment:11 by pierre, 4 months ago

Owner: changed from pierre to SecurityAdvisory
Status: assigned → new

Updated at 4a736de66c. Leaving open for SA

comment:12 by Douglas R. Reno, 3 months ago

Resolution: → fixed
Status: new → closed

SA-13.0-129 issued

Note: See TracTickets for help on using tickets.