Heap-Based Buffer Overflow in GNU LibreDWG Revealed
CVE-2026-9502
Key Information:
Badges
What is CVE-2026-9502?
A heap-based buffer overflow vulnerability has been discovered in GNU LibreDWG, specifically in the decompress_R2004_section function found in the src/decode.c component. This weakness enables an attacker to manipulate memory, potentially leading to execution of arbitrary code. The attack must be executed locally, and there are known exploits available publicly. To mitigate this vulnerability, users are advised to apply the official patch identified in commit e501cb9926c1e9a07a0d1cc997f3e69e9be801c9.
Affected Version(s)
LibreDWG 0.1
LibreDWG 0.2
LibreDWG 0.3
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved