CVE-2026-97222

Summary

A heap use-after-free flaw was found in Gnumeric. When a user opens a crafted Gnumeric workbook containing a malformed SheetObjectComponent element, the XML parser can dereference a freed sheet-object component, causing Gnumeric to crash.

Affected Software

VendorProductVersion RangeStatus
GNOMEGnumeric1.11.0 < *affected
GNOMEGnumericbc1dee29525933994181fb2307d6ad584de6040dunaffected

Weaknesses

  • CWE-416: Use After Free

Workarounds

Do not open Gnumeric workbook files from untrusted sources. No application-level mitigation that preserves processing of untrusted workbooks is known.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References