Out-of-Bounds Read Vulnerability in GNU LibreDWG by GNU
CVE-2026-9530
4.8MEDIUM
What is CVE-2026-9530?
A vulnerability in GNU LibreDWG, specifically in the read_2004_compressed_section function of the src/decode.c file, allows for out-of-bounds read operations. This vulnerability affects versions of the software up to 0.14 and requires local access to exploit. Once manipulated, it can potentially lead to unauthorized data access. Publicly available exploits have been developed, highlighting the importance of applying the provided patch (commit 8f03865f37f5d4ffd616fef802acc980be54d300) to mitigate this issue.
Affected Version(s)
LibreDWG 0.1
LibreDWG 0.2
LibreDWG 0.3
References
CVSS V4
Score:
4.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
Credit
pwn3rd (VulDB User)