A vulnerability was determined in GNU LibreDWG up to 0.14. The impacted element is the function decompress_R2004_section of the file src/decode.c of the component Dwgread Utility. Executing a manipulation can lead to reachable assertion. The attack is restricted to local execution. The exploit has been publicly disclosed and may be utilized. This patch is called e501cb9926c1e9a07a0d1cc997f3e69e9be801c9. A patch should be applied to remediate this issue.
Metrics
Affected Vendors & Products
References
History
Mon, 25 May 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was determined in GNU LibreDWG up to 0.14. The impacted element is the function decompress_R2004_section of the file src/decode.c of the component Dwgread Utility. Executing a manipulation can lead to reachable assertion. The attack is restricted to local execution. The exploit has been publicly disclosed and may be utilized. This patch is called e501cb9926c1e9a07a0d1cc997f3e69e9be801c9. A patch should be applied to remediate this issue. | |
| Title | GNU LibreDWG Dwgread Utility decode.c decompress_R2004_section assertion | |
| First Time appeared |
Gnu
Gnu libredwg |
|
| Weaknesses | CWE-617 | |
| CPEs | cpe:2.3:a:gnu:libredwg:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gnu
Gnu libredwg |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-05-25T20:30:14.389Z
Reserved: 2026-05-25T10:03:51.326Z
Link: CVE-2026-9501
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-05-25T21:30:06Z