LibreOffice Calc compiles cell formulas when opening a spreadsheet. (CVE-2026-8357)
LibreOffice Calc compiles cell formulas when opening a spreadsheet. A heap buffer overflow existed when compiling a very long formula made up of many opening tokens. The array that tracks nesting depth was allocated one element too small for that worst case, so such a formula wrote one element past its end. In fixed versions the array is sized to hold the largest possible nesting.
AI Analysis
Technical Summary
CVE-2026-8357 is a vulnerability in LibreOffice Calc where a heap buffer overflow occurs during formula compilation. This flaw can lead to arbitrary code execution. Red Hat Product Security has released an important security advisory (RHSA-2026:36832) addressing this issue in LibreOffice packages distributed with Red Hat Enterprise Linux 9 and its extended update support versions. The advisory includes updated packages to fix the vulnerability. No CVSS score is provided in the advisory, but the issue is rated as having a high security impact.
Potential Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system via a specially crafted formula in LibreOffice Calc. This could lead to compromise of the system running the vulnerable LibreOffice version. The advisory rates the impact as important (high severity). There are no known exploits in the wild at the time of the advisory.
Mitigation Recommendations
Red Hat has released updated LibreOffice packages for Red Hat Enterprise Linux 9 and related variants that fix this vulnerability. Users should apply the security update as described in the Red Hat advisory RHSA-2026:36832 and the linked article https://access.redhat.com/articles/11258. Since this is an official fix, applying the update fully mitigates the vulnerability.
LibreOffice Calc compiles cell formulas when opening a spreadsheet. (CVE-2026-8357)
Description
LibreOffice Calc compiles cell formulas when opening a spreadsheet. A heap buffer overflow existed when compiling a very long formula made up of many opening tokens. The array that tracks nesting depth was allocated one element too small for that worst case, so such a formula wrote one element past its end. In fixed versions the array is sized to hold the largest possible nesting.
CVSS v4.0
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-8357 is a vulnerability in LibreOffice Calc where a heap buffer overflow occurs during formula compilation. This flaw can lead to arbitrary code execution. Red Hat Product Security has released an important security advisory (RHSA-2026:36832) addressing this issue in LibreOffice packages distributed with Red Hat Enterprise Linux 9 and its extended update support versions. The advisory includes updated packages to fix the vulnerability. No CVSS score is provided in the advisory, but the issue is rated as having a high security impact.
Potential Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system via a specially crafted formula in LibreOffice Calc. This could lead to compromise of the system running the vulnerable LibreOffice version. The advisory rates the impact as important (high severity). There are no known exploits in the wild at the time of the advisory.
Mitigation Recommendations
Red Hat has released updated LibreOffice packages for Red Hat Enterprise Linux 9 and related variants that fix this vulnerability. Users should apply the security update as described in the Red Hat advisory RHSA-2026:36832 and the linked article https://access.redhat.com/articles/11258. Since this is an official fix, applying the update fully mitigates the vulnerability.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:36832
- Cve Count
- 1
- Additional Cves
- []
- Cvss Version
- null
Threat ID: 6a4f6c3668715ace431586d8
Added to database: 07/09/2026, 09:39:02 UTC
Last enriched: 07/09/2026, 09:51:22 UTC
Last updated: 07/31/2026, 19:24:49 UTC
Views: 86
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.