CVE-2026-63269

Description

A flaw was found in LibreOffice. When processing linked audio or video files on Linux systems, the application uses the GStreamer multimedia framework for playback. By convincing a victim to open a specially crafted document containing a malicious HTTP Live Streaming (HLS) playlist, an attacker can cause GStreamer to read arbitrary local files or remote resources. This flaw can lead to information disclosure, as the contents of sensitive local files may be exposed directly within the document.

Statement

A security flaw was found in LibreOffice on Linux platforms when rendering linked media files using the GStreamer framework. An attacker can exploit this by enticing a user to open a document with a crafted HTTP Live Streaming (HLS) playlist. When the document loads, GStreamer processes the playlist and reads local files or remote URLs specified within it. This can lead to sensitive local file contents being exposed directly inside the document context under the executing user's privileges.

Mitigation

Configure LibreOffice to restrict automatic link updating by navigating to Tools -> Options -> LibreOffice -> General and setting "Update links when loading" to "On request" or "Never". Alternatively, refrain from opening untrusted documents containing linked multimedia files.

Common Vulnerability Scoring System (CVSS) Score Details

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

The following CVSS metrics and score provided are preliminary and subject to review.

CVSS v3 Score Breakdown

Red HatNVDcve.org
Base Score5.5N/AN/A
Attack VectorLocalN/AN/A
Attack ComplexityLowN/AN/A
Privileges RequiredNoneN/AN/A
User InteractionRequiredN/AN/A
ScopeUnchangedN/AN/A
ConfidentialityHighN/AN/A
Integrity ImpactNoneN/AN/A
Availability ImpactNoneN/AN/A

Vector

Red Hat: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Understanding the Weakness (CWE)

Integrity,Confidentiality

Technical Impact: Read Files or Directories; Modify Files or Directories

The application can operate on unexpected files. Confidentiality is violated when the targeted filename is not directly readable by the attacker.

Integrity,Confidentiality,Availability

Technical Impact: Modify Files or Directories; Execute Unauthorized Code or Commands

The application can operate on unexpected files. This may violate integrity if the filename is written to, or if the filename is for a program or other form of executable code.

Availability

Technical Impact: DoS: Crash, Exit, or Restart; DoS: Resource Consumption (Other)

The application can operate on unexpected files. Availability can be violated if the attacker specifies an unexpected file that the application modifies. Availability can also be affected if the attacker specifies a filename for a large file, or points to a special device or a file that does not have the format that the application expects.

Frequently Asked Questions

Want to get errata notifications? Sign up here.