PT-2026-57607 · Gnu · Libredwg

·

CVE-2026-15520

·

Published

2026-07-01

·

Updated

2026-07-13

CVSS v3.1

5.3

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions GNU LibreDWG versions prior to 0.14.8396
Description A heap-based buffer overflow occurs in the R2004 Section Decompression component within the decompress R2004 section() function located in the src/decode.c file. This issue can be triggered through local access by executing a specific manipulation.
Recommendations Upgrade to version 0.14.8396.

Exploit

Fix

Heap Based Buffer Overflow

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09839
CVE-2026-15520
GHSA-QG2F-8389-W95J

Affected Products

Libredwg