Executive brief
GNU LibreDWG is a software library used to read and write DWG files, which are the native format for CAD software like AutoCAD. A vulnerability in the library's file handling component could allow a local user to cause a program crash (denial of service) by providing a specially crafted DWG file. This could disrupt operations for users or automated systems processing CAD data.
Technical details
A null pointer dereference exists in GNU LibreDWG versions up to and including 0.13.4 within the 'dwg_next_entity' function in 'src/dwg.c'. The vulnerability is triggered when the 'dwg_ref_object_silent' function returns a NULL pointer for the 'next_obj' argument, which is subsequently accessed without a proper null check during DWG entity traversal. An attacker with local access can exploit this by providing a malformed DWG file to a utility using the library (such as 'dwggrep'), leading to a segmentation fault and application crash. This issue has been resolved in version 0.14 by adding a check to ensure 'next_obj' is not NULL before access.
Affected products
- GNU LibreDWG up to 0.13.4
Timeline
- 2026-04-29: disclosed: Issue reported on GitHub with PoC
- 2026-06-27: patched: Version 0.14 released
- 2026-07-09: advisory: CVE-2026-15184 published
References
- https://github.com/HackC0der/CVE-Repos/blob/main/libredwg/libredwg_0b57303_dwggrep_segv_null_read_dwg_next_entity_dwg.c_1231.dwg
- https://github.com/LibreDWG/libredwg/commit/dde45dac3c4d902e4d8fed150a8017b9732019c9
- https://github.com/LibreDWG/libredwg/issues/1253
- https://github.com/LibreDWG/libredwg/releases/tag/0.14
- https://vuldb.com/cve/CVE-2026-15184
- https://vuldb.com/submit/851192
- https://vuldb.com/vuln/377110