PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-9530 GNU CVE debrief

A local out-of-bounds read vulnerability exists in GNU LibreDWG through version 0.14, specifically within the read_2004_compressed_section function in src/decode.c. The vulnerability affects the Dwgbmp Utility component and can be triggered through manipulation of DWG file processing. The issue was disclosed publicly on 2026-05-26 with a CVSS 4.0 score of 1.9 (LOW severity), reflecting the local attack vector and limited availability impact. A patch commit (8f03865f37f5d4ffd616fef802acc980be54d300) has been published to address this weakness. The vulnerability is classified under CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) and CWE-125 (Out-of-bounds Read).

Vendor
GNU
Product
LibreDWG
CVSS
LOW 1.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-26
Original CVE updated
2026-07-23
Advisory published
2026-05-26
Advisory updated
2026-07-23

Who should care

Organizations using GNU LibreDWG for DWG file processing, particularly in automated or multi-user environments where untrusted DWG files may be processed. System administrators maintaining CAD file conversion pipelines and developers integrating LibreDWG into document processing workflows should prioritize patching.

Technical summary

The vulnerability resides in the read_2004_compressed_section function within src/decode.c of GNU LibreDWG 0.14 and earlier. This function handles decompression of DWG file sections in the 2004 format. An out-of-bounds read can occur when processing malformed compressed section data, potentially leading to information disclosure or application instability. The attack requires local access to execute manipulation against the Dwgbmp Utility or other components utilizing the affected decode functionality.

Defensive priority

low

Recommended defensive actions

  • Apply the official patch commit 8f03865f37f5d4ffd616fef802acc980be54d300 from the LibreDWG repository
  • Upgrade to LibreDWG version 0.15 or later when available
  • Restrict local access to DWG file processing utilities on multi-user systems
  • Monitor for suspicious DWG file handling activity on affected systems
  • Validate DWG file inputs before processing through LibreDWG utilities

Evidence notes

The vulnerability was reported to VulDB (submission 814275) and assigned VulDB entry 365549. The issue was tracked as GitHub issue #1248 in the LibreDWG repository. The patch commit was made available through the official LibreDWG GitHub repository.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-9530 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-9530

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-9530 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-9530

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.