CVE-2025-2866

Title: PDF signature forgery with adbe.pkcs7.sha1 SubFilter

Announced: Apr 27, 2025

Fixed in: LibreOffice 24.8.6 and 25.2.2

Description:

LibreOffice supports digital signatures when opening PDF documents, presenting information if the signature is valid or not.

In the affected versions of LibreOffice a flaw in the verification code for adbe.pkcs7.sha1 signatures could cause invalid signatures to be accepted as valid

All users are recommended to upgrade to LibreOffice >= 24.8.6 or 25.2.2 to avoid this problem.

Credits:

  • Thanks to Juraj Šarinay for discovering this issue and for providing a fix.

References:

    CVE-2025-2866