Low severity3.3NVD Advisory· Published May 25, 2026· Updated Jul 23, 2026
CVE-2026-9504
CVE-2026-9504
Description
A weakness has been identified in GNU LibreDWG up to 0.14. Affected is the function bit_convert_TU of the file programs/dwggrep.c of the component Dwggrep Utility. This manipulation causes out-of-bounds read. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. Patch name: be996bf2178a40e98720f18c2414815d244413db. Applying a patch is the recommended action to fix this issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- Range: <=0.14
- osv-coords2 versionspkg:rpm/opensuse/libredwg&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/libredwg&distro=openSUSE%20Tumbleweed
< 0.14.8413-bp160.1.1+ 1 more
- (no CPE)range: < 0.14.8413-bp160.1.1
- (no CPE)range: < 0.13.4.8200-1.1
Patches
Vulnerability mechanics
References
7- github.com/HackC0der/CVE-Repos/blob/main/libredwg/libredwg_6d6a339_heap_overflow_bit_convert_TU.dwgnvd
- github.com/LibreDWG/libredwg/commit/be996bf2178a40e98720f18c2414815d244413dbnvd
- github.com/LibreDWG/libredwg/issues/1246nvd
- vuldb.com/submit/814261nvd
- vuldb.com/vuln/365486nvd
- vuldb.com/vuln/365486/ctinvd
- www.gnu.orgnvd
News mentions
0No linked articles in our index yet.