openSUSE-SU-2026:21346-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21346-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2026:21346-1
Upstream
CVE (9)
Related
Published
2026-07-13T10:19:51Z
Modified
2026-07-15T18:24:13Z
Summary
Security update for libredwg
Details

This update for libredwg fixes the following issues:

Changes in libredwg:

  • Update to snapshot 0.14.8413

    • fix dwg_next_entity NULL pointer dereference [CVE-2026-15184, boo#1271170]
    • Fix dwg_bmp thumbnail overflow checks [CVE-2026-15181, boo#1271169]
    • Resolve NULL pointer dereference (SEGV) in match_BLOCK_HEADER [CVE-2026-9529, boo#1266380]
    • Added DXB (binary DXF) support: dwgwrite/dwgread/dwg2dxf accept DXB input/output, and dxfwrite accepts DXB.
    • Minor features:
    • R2007+ split string stream encoding for Header, Classes, and objects.
    • Added cycle checks in entity link chains.
    • Added release helpers and improved CI (ODAFileConverter QT6, xvfb-run).
    • dwgfuzz: show mode with --version.
  • update to 0.14:

    • Write support for r2004 (AC1018) DWG files. The encoder now produces compressed, encrypted section headers and the LZ77-compressed object data layout required since r2004.
    • Split large object files (encode, decode) into 2 objects, significantly reducing peak memory usage during compilation and enabling parallel builds to scale better.
    • dwgadd: handle fields (e.g. layer, ltype, style) can now be set by table-record name in addition to raw handle references. A string value like line.layer = "FOO" is resolved via dwg_find_tablehandle() at parse time.
    • Added DXB (binary DXF) support: dwgwrite/dwgread/dwg2dxf accept DXB input/output, and dxfwrite accepts DXB.
    • R2007+ split string stream encoding for Header, Classes, and objects.
    • Added cycle checks in entity link chains. GH #1226.
    • Added regression tests for decompress_r2007 OOB reads and R2004 section decompression. Added dwgfilter.test.
    • Added release helpers and improved CI (ODAFileConverter QT6, xvfb-run).
    • dwgfuzz: show mode with --version.
    • API/ABI changes (source-incompatible):
    • Renamed HEADER/2NDHEADER.is_maint to maint_rel_version.
    • Renamed PROXY_OBJECT.dwg_versions.
    • Bumped SO_VERSION to 0:14:0.
  • Update to snapshot 0.13.4.8200

    • Write support for r2004 (AC1018) DWG files. The encoder now produces compressed, encrypted section headers and the LZ77-compressed object data layout required since r2004.
    • Split large object files (encode, decode) into 2 objects, significantly reducing peak memory usage during compilation and enabling parallel builds to scale better.
    • dwgadd: handle fields (e.g. layer, ltype, style) can now be set by table-record name in addition to raw handle references. A string value like line.layer = "FOO" is resolved via dwg_find_tablehandle() at parse time.
    • Fix decompress_R2004_section buffer overflow [CVE-2026-9501, CVE-2026-9502, CVE-2026-9529, CVE-2026-9530, boo#1266377, boo#1266378, boo#1266380, boo#1266287]
    • Fix dwg_next_entity NULL pointer dereference [CVE-2026-9503, boo#1266379]
    • Fix NULL pointer dereferences in DXF output for corrupted DWG input [CVE-2026-9504, boo#1266321]
    • decode: fix decompression overflow [CVE-2026-9605, boo#1266365]
References

Affected packages

openSUSE:Leap 16.0 / libredwg

Package

Name
libredwg
Purl
pkg:rpm/opensuse/libredwg&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.14.8413-bp160.1.1

Ecosystem specific

{
    "binaries":  [
        {
            "libredwg-devel":  "0.14.8413-bp160.1.1",
            "libredwg-tools":  "0.14.8413-bp160.1.1",
            "libredwg0":  "0.14.8413-bp160.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21346-1.json"