CVE-2026-6040: Red Hat Enterprise Linux 6

High severity, CVSS 7.3. EPSS: 0.2% chance of exploitation in the next 30 days.

A heap use-after-free existed when importing the blank-width characters of an ODF number format. A position value read from the document was not checked against the length of the format-code string, so a malformed number format could be processed against memory outside that string. In fixed versions the position is bounds-checked before use.

Affected products

  • Red Hat Red Hat Enterprise Linux 6
  • Red Hat Red Hat Enterprise Linux 7
  • Red Hat Red Hat Enterprise Linux 8
  • Red Hat Red Hat Enterprise Linux 9
  • The Document Foundation Libreoffice: from 25.8, before 25.8.7 (fixed in 25.8.7); from 26.2, before 26.2.3 (fixed in 26.2.3)

Published 2026-06-15. Last modified 2026-07-23.