PT-2026-43187 · Gnu · Libredwg

·

CVE-2026-9530

·

Published

2026-05-26

·

Updated

2026-07-13

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions GNU LibreDWG versions prior to 0.15
Description A weakness in the Dwgbmp Utility component allows an out-of-bounds read, which occurs when the system reads data outside the intended boundary of a buffer. This issue is located in the read 2004 compressed section() function within the src/decode.c file. Exploitation requires local access.
Recommendations Apply patch 8f03865f37f5d4ffd616fef802acc980be54d300 to resolve the issue. As a temporary workaround, restrict access to the read 2004 compressed section() function to minimize the risk of exploitation.

Exploit

Fix

Out of bounds Read

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-9530
OPENSUSE-SU-2026:21346-1

Affected Products

Libredwg