Out-of-Bounds Read Vulnerability in GNU LibreDWG by GNU
CVE-2026-9530
Key Information:
Badges
What is CVE-2026-9530?
A vulnerability in GNU LibreDWG, specifically in the read_2004_compressed_section function of the src/decode.c file, allows for out-of-bounds read operations. This vulnerability affects versions of the software up to 0.14 and requires local access to exploit. Once manipulated, it can potentially lead to unauthorized data access. Publicly available exploits have been developed, highlighting the importance of applying the provided patch (commit 8f03865f37f5d4ffd616fef802acc980be54d300) to mitigate this issue.
Affected Version(s)
LibreDWG 0.1
LibreDWG 0.2
LibreDWG 0.3
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved