Description
A vulnerability was found in GNU LibreDWG up to 0.14. The affected element is the function read_2004_compressed_section of the file src/decode.c of the component Dwgread Utility. Performing a manipulation results in heap-based buffer overflow. The attack is only possible with local access. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-05-25
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

For GNU LibreDWG versions up to 0.14, the function read_2004_compressed_section in src/decode.c can be triggered by a maliciously crafted .dwg file, causing a heap-based buffer overflow. The overflow corrupts adjacent heap objects and can result in application crashes or denial of service. The vulnerability is identified as CWE‑119 and CWE‑122.

Affected Systems

The impacted software is the LibreDWG Dwgread utility and any embedded C library built with versions 0.14 or earlier. Systems that process arbitrary .dwg files locally, or that allow local users to invoke the Dwgread utility, are within scope. No specific operating system or environment restrictions are indicated beyond the requirement of local file execution.

Risk and Exploitability

The CVSS v3.1 score of 4.8 indicates low severity. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires local access; an attacker must be able to run the Dwgread utility on the target machine and provide a crafted .dwg file. The exploit has been made public but there is no official patch yet, so the risk remains for any user or service that processes DWG files with LibreDWG.

Generated by OpenCVE AI on May 25, 2026 at 22:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • If a newer LibreDWG release includes the overflow fix, upgrade to that revision.
  • Limit execution of the Dwgread utility to trusted users or service accounts and remove or restrict access to it from publicly exposed directories.
  • Monitor application logs and system stability for crashes or abnormal behavior when processing DWG files, and ensure that untrusted file uploads are examined or sanitized before being passed to LibreDWG.

Generated by OpenCVE AI on May 25, 2026 at 22:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 26 May 2026 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 25 May 2026 20:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in GNU LibreDWG up to 0.14. The affected element is the function read_2004_compressed_section of the file src/decode.c of the component Dwgread Utility. Performing a manipulation results in heap-based buffer overflow. The attack is only possible with local access. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.
Title GNU LibreDWG Dwgread Utility decode.c read_2004_compressed_section heap-based overflow
First Time appeared Gnu
Gnu libredwg
Weaknesses CWE-119
CWE-122
CPEs cpe:2.3:a:gnu:libredwg:*:*:*:*:*:*:*:*
Vendors & Products Gnu
Gnu libredwg
References
Metrics cvssV2_0

{'score': 4.3, 'vector': 'AV:L/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-05-26T12:54:56.758Z

Reserved: 2026-05-25T10:03:48.361Z

Link: CVE-2026-9500

cve-icon Vulnrichment

Updated: 2026-05-26T12:54:40.880Z

cve-icon NVD

Status : Received

Published: 2026-05-25T21:16:35.680

Modified: 2026-05-26T14:16:44.547

Link: CVE-2026-9500

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-25T22:30:16Z

Weaknesses