High severity8.8NVD Advisory· Published Nov 19, 2021· Updated Jun 17, 2026
CVE-2021-21900
CVE-2021-21900
Description
A code execution vulnerability exists in the dxfRW::processLType() functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f3580. A specially-crafted .dxf file can lead to a use-after-free vulnerability. An attacker can provide a malicious file to trigger this vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
12cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
- LibreCad/libdxfrwdescription
- osv-coords4 versionspkg:rpm/opensuse/libdxfrw&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/librecad&distro=openSUSE%20Leap%2015.3pkg:rpm/suse/libdxfrw&distro=SUSE%20Package%20Hub%2015%20SP3pkg:rpm/suse/librecad&distro=SUSE%20Package%20Hub%2015%20SP3
< 1.0.1+git.20220109-bp153.2.3.1+ 3 more
- (no CPE)range: < 1.0.1+git.20220109-bp153.2.3.1
- (no CPE)range: < 2.2.0~rc3-bp153.2.3.1
- (no CPE)range: < 1.0.1+git.20220109-bp153.2.3.1
- (no CPE)range: < 2.2.0~rc3-bp153.2.3.1
Patches
Vulnerability mechanics
References
6- talosintelligence.com/vulnerability_reports/TALOS-2021-1351nvdBroken LinkExploitThird Party Advisory
- lists.debian.org/debian-lts-announce/2021/12/msg00002.htmlnvdMailing ListThird Party Advisory
- www.debian.org/security/2022/dsa-5077nvdThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RDI3HCTCACMIC7I4ILB3NRU6DCMADI5H/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZTIAMP7QJDKV4ADDLR4GVVX2TXYLHVOZ/nvd
- security.gentoo.org/glsa/202305-26nvd
News mentions
0No linked articles in our index yet.