A security flaw has been discovered in GNU LibreDWG up to 0.14. This impacts the function dwgnextentity of the file src/decode.c of the component DWG File Handler. The manipulation results in null pointer dereference. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The patch is identified as 8f03865f37f5d4ffd616fef802acc980be54d300. Upgrading the affected component is advised.
{
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "0.1"
},
{
"last_affected": "0.1"
},
{
"introduced": "0.2"
},
{
"last_affected": "0.2"
}
],
"source": "AFFECTED_FIELD"
}
],
"cna_assigner": "VulDB",
"cwe_ids": [
"CWE-404",
"CWE-476"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/9xxx/CVE-2026-9503.json"
}{
"extracted_events": [
{
"introduced": "0.3"
},
{
"last_affected": "0.3"
},
{
"introduced": "0.4"
},
{
"last_affected": "0.4"
},
{
"introduced": "0.5"
},
{
"last_affected": "0.5"
},
{
"introduced": "0.6"
},
{
"last_affected": "0.6"
},
{
"introduced": "0.7"
},
{
"last_affected": "0.7"
},
{
"introduced": "0.8"
},
{
"last_affected": "0.8"
},
{
"introduced": "0.9"
},
{
"last_affected": "0.9"
},
{
"introduced": "0.10"
},
{
"last_affected": "0.10"
},
{
"introduced": "0.11"
},
{
"last_affected": "0.11"
},
{
"introduced": "0.12"
},
{
"last_affected": "0.12"
},
{
"introduced": "0.13"
},
{
"last_affected": "0.13"
},
{
"introduced": "0.14"
},
{
"last_affected": "0.14"
}
],
"source": [
"AFFECTED_FIELD",
"REFERENCES"
]
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-9503.json"
[
{
"target": {
"file": "src/decode.c"
},
"deprecated": false,
"source": "https://github.com/libredwg/libredwg/commit/8f03865f37f5d4ffd616fef802acc980be54d300",
"id": "CVE-2026-9503-d5770181",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"35898828282133341884944571437441208822",
"111016291822501941201427952486376382974",
"204719403551589907799524301486078655452",
"321084837797370834700554236567059949717",
"82945914742827335401873043836341138986"
]
},
"signature_type": "Line"
},
{
"target": {
"function": "read_2004_compressed_section",
"file": "src/decode.c"
},
"deprecated": false,
"source": "https://github.com/libredwg/libredwg/commit/8f03865f37f5d4ffd616fef802acc980be54d300",
"id": "CVE-2026-9503-e9195089",
"signature_version": "v1",
"digest": {
"length": 6190.0,
"function_hash": "331313396876041992446712856981242496851"
},
"signature_type": "Function"
}
]
"2026-08-12T16:09:29Z"