6.9
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Description
A flaw has been found in GNU libredwg up to 0.13.4.8160. This issue affects the function bit_read_RC of the file bits.c of the component Dwgbmp Utility. This manipulation causes heap-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been published and may be used. Patch name: 8f03865f37f5d4ffd616fef802acc980be54d300. Applying a patch is the recommended action to fix this issue.
Basic Information
ID
CVE-2026-9605
Source
VulDB
Published
May 26, 2026 at 23:15
Affected Product
Vendor
GNU
Product
libredwg
Version
0.13.4.8160
Affected Versions
GNU libredwg 0.13.4.8160
CWE Classification
References
- vuldb.com /vuln/365678
- vuldb.com /vuln/365678/cti
- vuldb.com /submit/818197
- github.com /LibreDWG/libredwg/issues/1248
- github.com /HackC0der/CVE-Repos/blob/main/libredwg/libredwg_6d6a339_heap_oob_write_read_2004_compressed_section.dwg
- github.com /LibreDWG/libredwg/commit/8f03865f37f5d4ffd616fef802acc980be54d300
- www.gnu.org /