CVE-2026-6040: Red Hat Enterprise Linux 6
High severity, CVSS 7.3. EPSS: 0.2% chance of exploitation in the next 30 days.
A heap use-after-free existed when importing the blank-width characters of an ODF number format. A position value read from the document was not checked against the length of the format-code string, so a malformed number format could be processed against memory outside that string. In fixed versions the position is bounds-checked before use.
Affected products
- Red Hat Red Hat Enterprise Linux 6
- Red Hat Red Hat Enterprise Linux 7
- Red Hat Red Hat Enterprise Linux 8
- Red Hat Red Hat Enterprise Linux 9
- The Document Foundation Libreoffice: from 25.8, before 25.8.7 (fixed in 25.8.7); from 26.2, before 26.2.3 (fixed in 26.2.3)
Published 2026-06-15. Last modified 2026-07-23.