A flaw has been found in GNU libredwg up to 0.13.4.8160. This issue affects the function bitreadRC of the file bits.c of the component Dwgbmp Utility. This manipulation causes heap-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been published and may be used. Patch name: 8f03865f37f5d4ffd616fef802acc980be54d300. Applying a patch is the recommended action to fix this issue.
{
"cna_assigner": "VulDB",
"cwe_ids": [
"CWE-119",
"CWE-122"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/9xxx/CVE-2026-9605.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-9605.json"
[
{
"digest": {
"line_hashes": [
"35898828282133341884944571437441208822",
"111016291822501941201427952486376382974",
"204719403551589907799524301486078655452",
"321084837797370834700554236567059949717",
"82945914742827335401873043836341138986"
],
"threshold": 0.9
},
"id": "CVE-2026-9605-d5770181",
"signature_type": "Line",
"deprecated": false,
"signature_version": "v1",
"source": "https://github.com/libredwg/libredwg/commit/8f03865f37f5d4ffd616fef802acc980be54d300",
"target": {
"file": "src/decode.c"
}
},
{
"digest": {
"length": 6190.0,
"function_hash": "331313396876041992446712856981242496851"
},
"id": "CVE-2026-9605-e9195089",
"signature_type": "Function",
"deprecated": false,
"signature_version": "v1",
"source": "https://github.com/libredwg/libredwg/commit/8f03865f37f5d4ffd616fef802acc980be54d300",
"target": {
"function": "read_2004_compressed_section",
"file": "src/decode.c"
}
}
]
"2026-08-07T22:16:24Z"