PT-2026-43431 · Gnu · Libredwg

R1Ck9

·

Published

2026-04-22

·

Updated

2026-05-28

·

CVE-2026-9605

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions GNU libredwg versions prior to 0.13.4.8161
Description A heap-based buffer overflow occurs in the Dwgbmp Utility component within the bit read RC() function of the bits.c file. This flaw allows a remote attacker to trigger the overflow through specific manipulation.
Recommendations Apply patch 8f03865f37f5d4ffd616fef802acc980be54d300 to resolve the issue.

Exploit

Fix

Buffer Overflow

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2026-07480
CVE-2026-9605
OPENSUSE-SU-2026:10879-1

Affected Products

Libredwg