Junglewise Threat Intelligence

CVE-2026-15184: GNU LibreDWG null pointer dereference in dwg_next_entity

CVE-2026-15184 · Severity: low · CVSS 3.3 · Published 2026-07-09

Technologies: Gnu LibreDWG. Vendors: Gnu.

Executive brief

GNU LibreDWG is a software library used to read and write DWG files, which are the native format for CAD software like AutoCAD. A vulnerability in the library's file handling component could allow a local user to cause a program crash (denial of service) by providing a specially crafted DWG file. This could disrupt operations for users or automated systems processing CAD data.

Technical details

A null pointer dereference exists in GNU LibreDWG versions up to and including 0.13.4 within the 'dwg_next_entity' function in 'src/dwg.c'. The vulnerability is triggered when the 'dwg_ref_object_silent' function returns a NULL pointer for the 'next_obj' argument, which is subsequently accessed without a proper null check during DWG entity traversal. An attacker with local access can exploit this by providing a malformed DWG file to a utility using the library (such as 'dwggrep'), leading to a segmentation fault and application crash. This issue has been resolved in version 0.14 by adding a check to ensure 'next_obj' is not NULL before access.

Affected products

  • GNU LibreDWG up to 0.13.4

Timeline

  • 2026-04-29: disclosed: Issue reported on GitHub with PoC
  • 2026-06-27: patched: Version 0.14 released
  • 2026-07-09: advisory: CVE-2026-15184 published

References

Related threats