A weakness has been identified in GNU LibreDWG up to 0.14. Affected is the function bitconvertTU of the file programs/dwggrep.c of the component Dwggrep Utility. This manipulation causes out-of-bounds read. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. Patch name: be996bf2178a40e98720f18c2414815d244413db. Applying a patch is the recommended action to fix this issue.
{
"cna_assigner": "VulDB",
"cwe_ids": [
"CWE-119",
"CWE-125"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/9xxx/CVE-2026-9504.json",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "0.1"
},
{
"last_affected": "0.1"
},
{
"introduced": "0.2"
},
{
"last_affected": "0.2"
}
],
"source": "AFFECTED_FIELD"
}
]
}{
"extracted_events": [
{
"introduced": "0.3"
},
{
"last_affected": "0.3"
},
{
"introduced": "0.4"
},
{
"last_affected": "0.4"
},
{
"introduced": "0.5"
},
{
"last_affected": "0.5"
},
{
"introduced": "0.6"
},
{
"last_affected": "0.6"
},
{
"introduced": "0.7"
},
{
"last_affected": "0.7"
},
{
"introduced": "0.8"
},
{
"last_affected": "0.8"
},
{
"introduced": "0.9"
},
{
"last_affected": "0.9"
},
{
"introduced": "0.10"
},
{
"last_affected": "0.10"
},
{
"introduced": "0.11"
},
{
"last_affected": "0.11"
},
{
"introduced": "0.12"
},
{
"last_affected": "0.12"
},
{
"introduced": "0.13"
},
{
"last_affected": "0.13"
},
{
"introduced": "0.14"
},
{
"last_affected": "0.14"
}
],
"source": [
"AFFECTED_FIELD",
"REFERENCES"
]
}
[
{
"target": {
"file": "src/bits.h"
},
"signature_type": "Line",
"deprecated": false,
"signature_version": "v1",
"source": "https://github.com/libredwg/libredwg/commit/be996bf2178a40e98720f18c2414815d244413db",
"digest": {
"threshold": 0.9,
"line_hashes": [
"240795041863802980578403497924219477857",
"257957063292174060783859355506638938941",
"153663199416502278486998376755147394501",
"42741925966608602461546825548136814106",
"205704374111754188783906331831023023931",
"172983791612361623010395178469734116553",
"16108425747182538602891122044053861361",
"12753196683967824262179842586132381258",
"161044571099015027170791282954235955161"
]
},
"id": "CVE-2026-9504-04a18bc4"
},
{
"target": {
"file": "programs/dwggrep.c"
},
"signature_type": "Line",
"deprecated": false,
"signature_version": "v1",
"source": "https://github.com/libredwg/libredwg/commit/be996bf2178a40e98720f18c2414815d244413db",
"digest": {
"threshold": 0.9,
"line_hashes": [
"53531038607981974105738441162915743819",
"223646168636280542459783831738296341163",
"278026056577489998154935332886157637554",
"117366066285890919419892979506145269630"
]
},
"id": "CVE-2026-9504-3185292e"
},
{
"target": {
"function": "match_LTYPE",
"file": "programs/dwggrep.c"
},
"signature_type": "Function",
"deprecated": false,
"signature_version": "v1",
"source": "https://github.com/libredwg/libredwg/commit/be996bf2178a40e98720f18c2414815d244413db",
"digest": {
"function_hash": "322719291906259797903996674075834817877",
"length": 267.0
},
"id": "CVE-2026-9504-d0013c8f"
}
]
"2026-08-12T16:09:30Z"
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-9504.json"