PT-2026-56793 · Gnu · Libredwg

·

CVE-2026-15184

·

Published

2026-04-29

·

Updated

2026-07-13

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions GNU LibreDWG versions prior to 0.14
Description A null pointer dereference occurs in the DWG File Handler component when the next obj argument is manipulated within the dwg next entity() function located in the src/dwg.c file. This issue requires the attack to be initiated from a local position.
Recommendations Update GNU LibreDWG to version 0.14.

Exploit

Fix

Improper Resource Release

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09897
CVE-2026-15184
OPENSUSE-SU-2026:11247-1
OPENSUSE-SU-2026:21346-1

Affected Products

Libredwg