DEBIAN-CVE-2026-63270

Source
https://security-tracker.debian.org/tracker/CVE-2026-63270
Import Source
https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-63270.json
JSON Data
https://api.test.osv.dev/v1/vulns/DEBIAN-CVE-2026-63270
Upstream
  • CVE-2026-63270
Published
2026-10-05T12:17:11Z
Modified
2026-10-06T05:00:11Z
Severity
  • 6.7 (Medium) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
[none]
Details

URLs could be constructed which expanded environment variable or INI file values, so potentially sensitive information could be exfiltrated to a remote server on opening a document containing such links. The check added for CVE-2024-12426 did not cover every place a document can supply a URL. XForms instance data and the Calc csv and sql data providers still reached the expansion. In fixed versions these places refuse URLs with internal schemes when the URL comes from the document.

References

Affected packages

Debian:12 / libreoffice

Package

Name
libreoffice
Purl
pkg:deb/debian/libreoffice?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

4:7.*
4:7.4.5-3
4:7.4.7-1~bpo11+1
4:7.4.7-1
4:7.4.7-1+deb12u1~bpo11+1
4:7.4.7-1+deb12u1
4:7.4.7-1+deb12u2~bpo11+1
4:7.4.7-1+deb12u2
4:7.4.7-1+deb12u3
4:7.4.7-1+deb12u4
4:7.4.7-1+deb12u5
4:7.4.7-1+deb12u6
4:7.4.7-1+deb12u7
4:7.4.7-1+deb12u8
4:7.4.7-1+deb12u9
4:7.4.7-1+deb12u10
4:7.4.7-1+deb12u11
4:7.4.7-1+deb12u12
4:7.4.7-1+deb12u13
4:7.4.7-1+deb12u14
4:7.5.0~rc2-7
4:7.5.0~rc3-1
4:7.5.1~rc1-1
4:7.5.1~rc2-1
4:7.5.2~rc1-1
4:7.5.2~rc2-1
4:7.5.3~rc1-1
4:7.5.3~rc2-1
4:7.5.4~rc1-1
4:7.5.4~rc1-2
4:7.5.4~rc1-3
4:7.5.4~rc1-4
4:7.5.4~rc2-1
4:7.5.4-1
4:7.5.4-2
4:7.5.4-3
4:7.5.4-4
4:7.5.5~rc1-1
4:7.5.5~rc1-2
4:7.5.5~rc1-3
4:7.5.5~rc1-4
4:7.5.5~rc1-5
4:7.5.5~rc2-1
4:7.5.5-1
4:7.5.5-2
4:7.5.5-3~bpo12+1
4:7.5.5-3
4:7.5.5-4~bpo12+1
4:7.5.5-4
4:7.5.6-1~bpo12+1
4:7.5.6-1
4:7.5.7-1
4:7.5.8~rc1-1
4:7.5.8~rc1-2
4:7.5.8-1~bpo12+1
4:7.5.8-1
4:7.5.9~rc1-1~bpo12+1
4:7.5.9~rc1-1~bpo12+2
4:7.5.9~rc1-1
4:7.6.0~rc1-1
4:7.6.0~rc1-2
4:7.6.0~rc2-1
4:7.6.0~rc2-2
4:7.6.0~rc3-1
4:7.6.1~rc1-1
4:7.6.1~rc2-1
4:7.6.1~rc2-2
4:7.6.2-1
4:7.6.2-2
4:7.6.2-3
4:7.6.2-4
4:7.6.2-5
4:7.6.3~rc1-1
4:7.6.3~rc1-2
4:7.6.3~rc2-1
4:7.6.3~rc2-2
4:7.6.3-1
4:7.6.3-2
4:7.6.4~rc1-1~bpo12+1
4:7.6.4~rc1-1
4:24.*
4:24.2.0~alpha1-1
4:24.2.0~beta1-1
4:24.2.0~rc1-1
4:24.2.0~rc1-2
4:24.2.0~rc2-1
4:24.2.0~rc2-2~bpo12+1
4:24.2.0~rc2-2
4:24.2.0-1~bpo12+1
4:24.2.0-1
4:24.2.0-2
4:24.2.0-3
4:24.2.1~rc1-1
4:24.2.1~rc2-1
4:24.2.1-1
4:24.2.1-2
4:24.2.1-3
4:24.2.1-4
4:24.2.2~rc1-1
4:24.2.2~rc1-2
4:24.2.2~rc2-1
4:24.2.2~rc2-2
4:24.2.2-1
4:24.2.2-2
4:24.2.2-3
4:24.2.3~rc1-1
4:24.2.3~rc1-2
4:24.2.3~rc1-3
4:24.2.3~rc2-1
4:24.2.3-1~bpo12+1
4:24.2.3-1
4:24.2.3-2
4:24.2.4-1~bpo12+1
4:24.2.4-1
4:24.2.5-1~bpo12+1
4:24.2.5-1
4:24.2.5-2
4:24.2.5-3
4:24.2.5-4
4:24.2.6-1
4:24.2.6-2~bpo12+1
4:24.2.6-2
4:24.8.0~alpha1-1
4:24.8.0~alpha1-2
4:24.8.0~alpha1-3
4:24.8.0~alpha1-4
4:24.8.0~beta1-1
4:24.8.0~rc1-1
4:24.8.0~rc2-1
4:24.8.0~rc3-1
4:24.8.0~rc3-2
4:24.8.1~rc1-1
4:24.8.1-1
4:24.8.1-2
4:24.8.2~rc1-1
4:24.8.2-1~bpo12+1
4:24.8.2-1
4:24.8.2-2
4:24.8.3-1~bpo12+1
4:24.8.3-1
4:24.8.3-2
4:24.8.3-3
4:24.8.4-1~bpo12+1
4:24.8.4-1
4:24.8.4-2
4:24.8.4-3
4:24.8.4-4
4:24.8.5-1
4:24.8.5-2~bpo12+1
4:24.8.5-2~bpo12+2
4:24.8.5-2
4:25.*
4:25.2.0~alpha1-1
4:25.2.0~beta1-1
4:25.2.0~beta1-2
4:25.2.0~rc1-1
4:25.2.0~rc1-2
4:25.2.0~rc1-3
4:25.2.0~rc1-4
4:25.2.0~rc2-1
4:25.2.0~rc3-1
4:25.2.0~rc3-2
4:25.2.1~rc1-1
4:25.2.1~rc1-2
4:25.2.1~rc2-1
4:25.2.1-1
4:25.2.1-2
4:25.2.1-3~bpo12+1
4:25.2.1-3
4:25.2.2~rc1-1
4:25.2.2~rc2-1
4:25.2.2-1~bpo12+1
4:25.2.2-1
4:25.2.2-2
4:25.2.2-3~bpo12+1
4:25.2.2-3
4:25.2.3~rc1-1
4:25.2.3~rc1-2
4:25.2.3~rc2-1
4:25.2.3-1
4:25.2.3-2~bpo12+1
4:25.2.3-2
4:25.8.0~alpha1-1
4:25.8.0~alpha1-2
4:25.8.0~beta1-1
4:25.8.0~rc1-1
4:25.8.0~rc1-2
4:25.8.0~rc2-1
4:25.8.0~rc2-2
4:25.8.0~rc3-1
4:25.8.0~rc4-1
4:25.8.0~rc4-2
4:25.8.0-1~bpo13+1
4:25.8.0-1
4:25.8.1~rc1-1
4:25.8.1-1~bpo13+1
4:25.8.1-1
4:25.8.2~rc1-1
4:25.8.2~rc2-1
4:25.8.2-1
4:25.8.2-2
4:25.8.2-3~bpo13+1
4:25.8.2-3
4:25.8.3~rc1-1
4:25.8.3~rc2-1
4:25.8.3-1~bpo13+1
4:25.8.3-1
4:25.8.3-1+ports
4:25.8.4-1~bpo13+1
4:25.8.4-1
4:26.*
4:26.2.0~alpha1-1
4:26.2.0~alpha1-2
4:26.2.0~alpha1-3
4:26.2.0~beta1-1
4:26.2.0~rc1-1
4:26.2.0~rc2-1
4:26.2.0~rc3-1
4:26.2.0-1~bpo13+1
4:26.2.0-1
4:26.2.1~rc1-1
4:26.2.1~rc2-1
4:26.2.1-1~bpo13+1
4:26.2.1-1
4:26.2.2.1-1
4:26.2.2.1-2
4:26.2.2.2-1
4:26.2.2.2-2
4:26.2.2.2-3~bpo13+1
4:26.2.2.2-3
4:26.2.3.1-1
4:26.2.3.2-1
4:26.2.3.2-2~bpo13+1
4:26.2.3.2-2
4:26.2.4.1-1
4:26.2.4.2-1~bpo13+1
4:26.2.4.2-1
4:26.2.4.2-2
4:26.2.5.2-1
4:26.2.5.2-2~bpo13+1
4:26.2.5.2-2
4:26.8.0.0.alpha1-1
4:26.8.0.0.alpha1-2
4:26.8.0.0.alpha1-3
4:26.8.0.0.alpha1-4
4:26.8.0.0.beta1-1
4:26.8.0.1-1
4:26.8.0.2-1
4:26.8.0.3-1
4:26.8.0.3-2~bpo13+1
4:26.8.0.3-2
4:26.8.1.1-1
4:26.8.1.1-2
4:26.8.1.1-3

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-63270.json"

Debian:13 / libreoffice

Package

Name
libreoffice
Purl
pkg:deb/debian/libreoffice?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4:25.2.3-2+deb13u8

Affected versions

4:25.*
4:25.2.3-2
4:25.2.3-2+deb13u1
4:25.2.3-2+deb13u2~bpo12+1
4:25.2.3-2+deb13u2
4:25.2.3-2+deb13u3~bpo12+1
4:25.2.3-2+deb13u3
4:25.2.3-2+deb13u4
4:25.2.3-2+deb13u5~bpo12+1
4:25.2.3-2+deb13u5
4:25.2.3-2+deb13u6
4:25.2.3-2+deb13u7

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-63270.json"

Debian:14 / libreoffice

Package

Name
libreoffice
Purl
pkg:deb/debian/libreoffice?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4:26.2.5.2-1

Affected versions

4:25.*
4:25.2.3-2
4:25.8.0~alpha1-1
4:25.8.0~alpha1-2
4:25.8.0~beta1-1
4:25.8.0~rc1-1
4:25.8.0~rc1-2
4:25.8.0~rc2-1
4:25.8.0~rc2-2
4:25.8.0~rc3-1
4:25.8.0~rc4-1
4:25.8.0~rc4-2
4:25.8.0-1~bpo13+1
4:25.8.0-1
4:25.8.1~rc1-1
4:25.8.1-1~bpo13+1
4:25.8.1-1
4:25.8.2~rc1-1
4:25.8.2~rc2-1
4:25.8.2-1
4:25.8.2-2
4:25.8.2-3~bpo13+1
4:25.8.2-3
4:25.8.3~rc1-1
4:25.8.3~rc2-1
4:25.8.3-1~bpo13+1
4:25.8.3-1
4:25.8.3-1+ports
4:25.8.4-1~bpo13+1
4:25.8.4-1
4:26.*
4:26.2.0~alpha1-1
4:26.2.0~alpha1-2
4:26.2.0~alpha1-3
4:26.2.0~beta1-1
4:26.2.0~rc1-1
4:26.2.0~rc2-1
4:26.2.0~rc3-1
4:26.2.0-1~bpo13+1
4:26.2.0-1
4:26.2.1~rc1-1
4:26.2.1~rc2-1
4:26.2.1-1~bpo13+1
4:26.2.1-1
4:26.2.2.1-1
4:26.2.2.1-2
4:26.2.2.2-1
4:26.2.2.2-2
4:26.2.2.2-3~bpo13+1
4:26.2.2.2-3
4:26.2.3.1-1
4:26.2.3.2-1
4:26.2.3.2-2~bpo13+1
4:26.2.3.2-2
4:26.2.4.1-1
4:26.2.4.2-1~bpo13+1
4:26.2.4.2-1
4:26.2.4.2-2

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-63270.json"