A vulnerability has been found in GNU LibreDWG up to 0.13.4. The affected element is the function dwg_bmp of the file src/dwg.c of the component BMP Image Handler. Such manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. Upgrading to version 0.14 is sufficient to fix this issue. The name of the patch is 18fd542bb4d5ccedf9de12052bf50068b2b26f06. It is suggested to upgrade the affected component.
{
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "0.13.0"
},
{
"last_affected": "0.13.0"
}
],
"source": "AFFECTED_FIELD"
}
],
"cwe_ids": [
"CWE-119",
"CWE-122"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/15xxx/CVE-2026-15182.json",
"cna_assigner": "VulDB"
}{
"extracted_events": [
{
"introduced": "0.13.1"
},
{
"last_affected": "0.13.1"
},
{
"introduced": "0.13.2"
},
{
"last_affected": "0.13.2"
},
{
"introduced": "0.13.3"
},
{
"last_affected": "0.13.3"
},
{
"introduced": "0.13.4"
},
{
"last_affected": "0.13.4"
}
],
"source": [
"AFFECTED_FIELD",
"REFERENCES"
]
}
[
{
"target": {
"file": "src/dwg.c"
},
"id": "CVE-2026-15182-0da5306f",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"295707233892739937723353010087032883170",
"143445880972127037809875106623164670727",
"246069498478684131686266605149549549710",
"312227386175570478050064856903584336064",
"272750108539434613787339734526588462857",
"182261718885084257790457337682035413667",
"31486674230858960773790296304743944240",
"91505033929580000129121325029363683881",
"207726363867453517319354738460819713374",
"240843749542445239201057216204624195326",
"313393336952015825309931672404524659779",
"124337050641225231936986723748904758901",
"204022244525052662165371483021557106982",
"269888458706998854536876769201893319797",
"91678441934123846630608476246297396548",
"80858159196168257964581497704156502524",
"218472603230435992732068077787711377580",
"292462290231329160356600746571467450993",
"282124129540975665799072960972641983593",
"29854988804978305640036585891197292014",
"133092722065923035155128702265987563614"
]
},
"signature_version": "v1",
"source": "https://github.com/libredwg/libredwg/commit/18fd542bb4d5ccedf9de12052bf50068b2b26f06",
"deprecated": false
},
{
"target": {
"file": "src/encode.c"
},
"id": "CVE-2026-15182-9d8b7cb7",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"49767515012856523006609786846141487675",
"51767973309089573731138741627418469522",
"214988644504213162965813640952238262990",
"244819296756283961456692824590706746832",
"27844949856869863672095217557809784032",
"77896253088770974522687231449032865388",
"109656386444620635452392358778299269116",
"296031323750994905362176623140475984053",
"106201200356465986227145837673662370733",
"30256074524972750250787441305293718266",
"173369055911681301747166990024197824583",
"143621292742105292688096803105989929264",
"65876926228280999514100252927459455022",
"85392031684084465774002464460570711921",
"249238180479009043757627070605456909292",
"195222699048597012469761422123501115447"
]
},
"signature_version": "v1",
"source": "https://github.com/libredwg/libredwg/commit/d9468ae948b8f07a08efa756c19f8916052358c0",
"deprecated": false
},
{
"target": {
"file": "examples/dwgfuzz.c"
},
"id": "CVE-2026-15182-d1ac7042",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"154512130852018455397856659198690717106",
"51876481842413898283512797170439118054",
"174184467050061406361915063095242200094",
"72521053116087091797231805787808258915",
"294587100473962440125218262153547687185",
"291013262779701407238566580163244165335",
"286715408555221545764630641579777262070",
"188660135417106434958253696063144996382",
"251312105046776457484298978991698236668",
"95784509257409776765300152242340662557",
"173539188606416070312364628183834824913",
"249782971859245451613310168160955920048",
"226235201698424972492719238058069981173"
]
},
"signature_version": "v1",
"source": "https://github.com/libredwg/libredwg/commit/d9468ae948b8f07a08efa756c19f8916052358c0",
"deprecated": false
},
{
"target": {
"function": "main",
"file": "examples/dwgfuzz.c"
},
"id": "CVE-2026-15182-d6d3b436",
"signature_type": "Function",
"digest": {
"function_hash": "268448865954434003822748246748691671176",
"length": 5110.0
},
"signature_version": "v1",
"source": "https://github.com/libredwg/libredwg/commit/d9468ae948b8f07a08efa756c19f8916052358c0",
"deprecated": false
},
{
"target": {
"function": "dwg_bmp",
"file": "src/dwg.c"
},
"id": "CVE-2026-15182-f7557be7",
"signature_type": "Function",
"digest": {
"function_hash": "90490400448932804892569284493956734611",
"length": 2829.0
},
"signature_version": "v1",
"source": "https://github.com/libredwg/libredwg/commit/18fd542bb4d5ccedf9de12052bf50068b2b26f06",
"deprecated": false
}
]
"2026-08-12T15:31:26Z"
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-15182.json"