PT-2026-91040 · Gnu · Libredwg

·

CVE-2026-90622

·

Published

2026-09-14

·

Updated

2026-09-15

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions GNU libredwg version 0.13.4
Description A security flaw in the Layer Encoding component exists within the DWG TABLE() function of the src/dwg.spec file. A local manipulation can lead to a null pointer dereference, which occurs when raw zeroing assignments dereference a NULL material handle. This happens because the FIELD HANDLE macro is NULL-safe, but specific assignments added to disable LAYER.material bypassed the existing if ( obj->style) guard convention.
Recommendations Upgrade to version 0.14.

Exploit

Fix

Improper Resource Release

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-90622

Affected Products

Libredwg