CVE-2026-9529: GNU LibreDWG Dwggrep Utility dwggrep.c match_BLOCK_HEADER null pointer dereference
A security flaw has been discovered in GNU LibreDWG up to 0.14. The affected element is the function matchBLOCKHEADER of the file dwggrep.c of the component Dwggrep Utility. Performing a manipulation results in null pointer dereference. The attack requires a local approach. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9529?
The severity of CVE-2026-9529 is classified as low with a score of 3.3.
How do I fix CVE-2026-9529?
To fix CVE-2026-9529, update GNU LibreDWG to the latest version that resolves this null pointer dereference issue.
What is the impact of CVE-2026-9529?
CVE-2026-9529 can lead to a null pointer dereference which may cause the application to crash.
Where is CVE-2026-9529 found?
CVE-2026-9529 is found in the match_BLOCK_HEADER function within the dwggrep.c file of GNU LibreDWG.
What type of attacks can exploit CVE-2026-9529?
Exploitation of CVE-2026-9529 requires a local attack vector to trigger the null pointer dereference.