CVE-2026-9503

Severity CVSS v4.0:
LOW
Type:
CWE-404 Improper Resource Shutdown or Release
Publication date:
25/05/2026
Last modified:
25/05/2026

Description

A security flaw has been discovered in GNU LibreDWG up to 0.14. This impacts the function dwg_next_entity of the file src/decode.c of the component DWG File Handler. The manipulation results in null pointer dereference. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The patch is identified as 8f03865f37f5d4ffd616fef802acc980be54d300. Upgrading the affected component is advised.