CVE-2025-61154: Buffer Overflow
Published Mar 12, 2026
·Updated
Heap buffer overflow vulnerability in LibreDWG versions v0.13.3.7571 up to v0.13.3.7835 allows a crafted DWG file to cause a Denial of Service (DoS) via the function decompressR2004section at decode.c.
Affected Software
2 affected components
LibreDWG LibreDWG>=0.13.3.7571<=0.13.3.7835
GNU LibreDWG>=0.13.3.7571<=0.13.3.7835
Event History
Mar 12, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-61154?
The severity of CVE-2025-61154 is classified as medium with a CVSS score of 6.5.
2
How does CVE-2025-61154 exploit a vulnerability in LibreDWG?
CVE-2025-61154 exploits a heap buffer overflow in LibreDWG that can be triggered by a specially crafted DWG file.
3
What are the potential impacts of CVE-2025-61154?
The primary impact of CVE-2025-61154 is a Denial of Service (DoS), leading to application crashes.
4
Which versions of LibreDWG are affected by CVE-2025-61154?
CVE-2025-61154 affects LibreDWG versions from v0.13.3.7571 up to v0.13.3.7835.
5
How can I mitigate the risks associated with CVE-2025-61154?
Mitigation for CVE-2025-61154 involves updating LibreDWG to a version that is not affected by the vulnerability.