CVE-2026-9504: GNU LibreDWG Dwggrep Utility dwggrep.c bit_convert_TU out-of-bounds
A weakness has been identified in GNU LibreDWG up to 0.14. Affected is the function bitconvertTU of the file programs/dwggrep.c of the component Dwggrep Utility. This manipulation causes out-of-bounds read. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. Patch name: be996bf2178a40e98720f18c2414815d244413db. Applying a patch is the recommended action to fix this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GNU LibreDWG Dwggrep Utility (bit_convert_TU in programs/dwggrep.c)to a version that resolves this vulnerability.Patch be996bf2178a40e98720f18c2414815d244413db
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9504?
The severity of CVE-2026-9504 is classified as low with a score of 3.3.
How do I fix CVE-2026-9504?
To fix CVE-2026-9504, you should update to GNU LibreDWG version 0.15 or later.
What type of vulnerability is CVE-2026-9504?
CVE-2026-9504 is categorized as a buffer overflow vulnerability leading to out-of-bounds read.
Can CVE-2026-9504 be exploited remotely?
No, CVE-2026-9504 requires local access to exploit the vulnerability.
What component of GNU LibreDWG is affected by CVE-2026-9504?
CVE-2026-9504 affects the Dwggrep Utility, specifically the function bit_convert_TU in the dwggrep.c file.