Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 26 May 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 25 May 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A weakness has been identified in GNU LibreDWG up to 0.14. Affected is the function bit_convert_TU of the file programs/dwggrep.c of the component Dwggrep Utility. This manipulation causes out-of-bounds read. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. Patch name: be996bf2178a40e98720f18c2414815d244413db. Applying a patch is the recommended action to fix this issue. | |
| Title | GNU LibreDWG Dwggrep Utility dwggrep.c bit_convert_TU out-of-bounds | |
| First Time appeared |
Gnu
Gnu libredwg |
|
| Weaknesses | CWE-119 CWE-125 |
|
| CPEs | cpe:2.3:a:gnu:libredwg:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gnu
Gnu libredwg |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-05-26T15:11:22.474Z
Reserved: 2026-05-25T10:04:28.109Z
Link: CVE-2026-9504
Updated: 2026-05-26T15:11:18.488Z
Status : Deferred
Published: 2026-05-25T22:16:34.153
Modified: 2026-06-17T11:05:23.267
Link: CVE-2026-9504
No data.
OpenCVE Enrichment
Updated: 2026-05-26T01:00:11Z