Gnu · Libredwg · CVE-2026-15182
**Name of the Vulnerable Software and Affected Versions**
GNU LibreDWG versions prior to 0.14
**Description**
A heap-based buffer overflow occurs in the BMP Image Handler component within the `dwg bmp()` function located in the src/dwg.c file. This issue requires local access to be exploited.
**Recommendations**
Update to version 0.14.
As a temporary mitigation, restrict the use of the `dwg bmp()` function.