Description
A security flaw has been discovered in GNU libredwg 0.13.4. This impacts the function DWG_TABLE of the file src/dwg.spec of the component Layer Encoding. Performing a manipulation results in null pointer dereference. The attack needs to be approached locally. The exploit has been released to the public and may be used for attacks. Upgrading to version 0.14 will fix this issue. The patch is named f5b548c4c1697d66c3dabd0f6a49280a14365a3a. The affected component should be upgraded. The FIELD_HANDLE macro itself is NULL-safe (emits null_handle) - only the two raw zeroing assignments added by 27118c40 ("encode: also disable LAYER.material") dereferenced a NULL material handle; the fix restores the file's existing if (_obj->style) guard convention for material.
Published: 2026-09-14
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Local Denial of Service via null pointer dereference
Action: Apply Patch
AI Analysis

Impact

The flaw resides in the DWG_TABLE function within the Layer Encoding component of GNU libredwg file causes the function to dereference a null pointer when handling a material handle that was forcefully zeroed. The dereference results in a program crash condition for any process that parses the file. The description specifically calls this a null pointer dereference triggered by local manipulation local attacker could cause the crash.

Affected Systems

Affected systems are those using GNU libredwg version 0.13.4 or earlier. The advisory recommends upgrading to version 0.14, which re‑introduces the guard against dereferencing a null handle. The patch (commit f5b548c4c1697d66c3dabd0f6a49280a14365a3a) was released on github and is included libredwg viewer applications, conversion tools, or scripts – should apply the update immediately.

Risk and Exploitability

The CVSS score of 4.8 reflects a medium severity, primarily due to the local scope of the attack vector. The EPSS score of <1% indicates a very low probability of exploitation by the general population, but the existence of a public exploit and the ability to trigger the flaw by manipulating a DWG file makes it realistic for systems that run untrusted files locally. Because the impact is denial‑of‑service rather than arbitrary code execution, the threat level is limited but still significant for environments requiring high availability. The vulnerability is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on September 15, 2026 at 16:03 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update GNU libredwg to version 0.14 or later, which removes the unsafe zeroing of the material handle.
  • Configure any CAD or file‑processing tools that use GNU libredwg to run with the lowest privilege possible to contain the effect of a crash.
  • After applying the update, monitor application logs for unexpected crashes and keep the library up‑to‑date with future releases.

Generated by OpenCVE AI on September 15, 2026 at 16:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 03:45:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in GNU libredwg 0.13.4. This impacts the function DWG_TABLE of the file src/dwg.spec of the component Layer Encoding. Performing a manipulation results in null pointer dereference. The attack needs to be approached locally. The exploit has been released to the public and may be used for attacks. Upgrading to version 0.14 will fix this issue. The patch is named f5b548c4c1697d66c3dabd0f6a49280a14365a3a. The affected component should be upgraded. The FIELD_HANDLE macro itself is NULL-safe (emits null_handle) - only the two raw zeroing assignments added by 27118c40 ("encode: also disable LAYER.material") dereferenced a NULL material handle; the fix restores the file's existing if (_obj->style) guard convention for material.
Title GNU libredwg Layer Encoding dwg.spec DWG_TABLE null pointer dereference
First Time appeared Gnu
Gnu libredwg
Weaknesses CWE-404
CWE-476
CPEs cpe:2.3:a:gnu:libredwg:*:*:*:*:*:*:*:*
Vendors & Products Gnu
Gnu libredwg
References
Metrics cvssV2_0

{'score': 1.7, 'vector': 'AV:L/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 3.3, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T17:28:33.472Z

Reserved: 2026-09-12T20:27:01.101Z

Link: CVE-2026-90622

cve-icon Vulnrichment

Updated: 2026-09-15T17:28:07.355Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T04:16:35.913

Modified: 2026-09-15T18:19:37.603

Link: CVE-2026-90622

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T16:15:15Z

Weaknesses
  • CWE-404

    Improper Resource Shutdown or Release

  • CWE-476

    NULL Pointer Dereference