An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to a stack overflow in bits.c, possibly related to bitreadTF.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-20912.json"
"2026-04-11T09:40:06Z"
[
{
"signature_version": "v1",
"signature_type": "Function",
"source": "https://github.com/libredwg/libredwg/commit/b84c2cab55948a5ee70860779b2640913e3ee1ed",
"digest": {
"function_hash": "96338434088265487358644619236390278650",
"length": 523.0
},
"id": "CVE-2019-20912-6862cdb7",
"deprecated": false,
"target": {
"file": "src/bits.c",
"function": "bit_write_UMC"
}
},
{
"signature_version": "v1",
"signature_type": "Line",
"source": "https://github.com/libredwg/libredwg/commit/b84c2cab55948a5ee70860779b2640913e3ee1ed",
"digest": {
"threshold": 0.9,
"line_hashes": [
"113052727542273460921737678445611708993",
"152939320705181754443722810749730501374",
"288378964425942374801464293818649235698",
"192192677306202081307193547809927986179"
]
},
"id": "CVE-2019-20912-6e88b68b",
"deprecated": false,
"target": {
"file": "src/bits.c"
}
}
]