A vulnerability was determined in GNU LibreDWG up to 0.14. The impacted element is the function decompressR2004section of the file src/decode.c of the component Dwgread Utility. Executing a manipulation can lead to reachable assertion. The attack is restricted to local execution. The exploit has been publicly disclosed and may be utilized. This patch is called e501cb9926c1e9a07a0d1cc997f3e69e9be801c9. A patch should be applied to remediate this issue.
{
"cwe_ids": [
"CWE-617"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/9xxx/CVE-2026-9501.json",
"cna_assigner": "VulDB",
"unresolved_ranges": [
{
"source": "AFFECTED_FIELD",
"extracted_events": [
{
"introduced": "0.1"
},
{
"last_affected": "0.1"
},
{
"introduced": "0.2"
},
{
"last_affected": "0.2"
}
]
}
]
}{
"source": [
"AFFECTED_FIELD",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "0.3"
},
{
"last_affected": "0.3"
},
{
"introduced": "0.4"
},
{
"last_affected": "0.4"
},
{
"introduced": "0.5"
},
{
"last_affected": "0.5"
},
{
"introduced": "0.6"
},
{
"last_affected": "0.6"
},
{
"introduced": "0.7"
},
{
"last_affected": "0.7"
},
{
"introduced": "0.8"
},
{
"last_affected": "0.8"
},
{
"introduced": "0.9"
},
{
"last_affected": "0.9"
},
{
"introduced": "0.10"
},
{
"last_affected": "0.10"
},
{
"introduced": "0.11"
},
{
"last_affected": "0.11"
},
{
"introduced": "0.12"
},
{
"last_affected": "0.12"
},
{
"introduced": "0.13"
},
{
"last_affected": "0.13"
},
{
"introduced": "0.14"
},
{
"last_affected": "0.14"
}
]
}"2026-07-25T08:12:13Z"
[
{
"signature_type": "Line",
"target": {
"file": "src/decode.c"
},
"deprecated": false,
"source": "https://github.com/libredwg/libredwg/commit/e501cb9926c1e9a07a0d1cc997f3e69e9be801c9",
"id": "CVE-2026-9501-27526e10",
"signature_version": "v1",
"digest": {
"line_hashes": [
"141046440839627751781400256495473738906",
"44492205633022103736388910009573031648",
"270957581276138494969156722045023542228",
"55380209146917572618342686645289787509"
],
"threshold": 0.9
}
},
{
"signature_type": "Function",
"target": {
"file": "src/decode.c",
"function": "decompress_R2004_section"
},
"deprecated": false,
"source": "https://github.com/libredwg/libredwg/commit/e501cb9926c1e9a07a0d1cc997f3e69e9be801c9",
"id": "CVE-2026-9501-5e1e7c0e",
"signature_version": "v1",
"digest": {
"function_hash": "54093846780705705489476850069579466663",
"length": 2708.0
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-9501.json"