CVE-2026-15520
published 2026-07-13CVE-2026-15520: A vulnerability was determined in GNU LibreDWG 0.13.4-154-g0b573035. This impacts the function decompress_R2004_section of the file src/decode.c of the…
PriorityP430medium5.3CVSS 3.1
AVLACLPRLUINSUCLILAL
EPSS
0.14%
3.5th percentile
A vulnerability was determined in GNU LibreDWG 0.13.4-154-g0b573035. This impacts the function decompress_R2004_section of the file src/decode.c of the component R2004 Section Decompression. Executing a manipulation can lead to heap-based buffer overflow. The attack requires local access. The exploit has been publicly disclosed and may be utilized. Upgrading to version 0.14.8396 will fix this issue. This patch is called 3d0f9fc2eddbd6579c99af3111c37c98f03475d0. You should upgrade the affected component.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnu | libredwg | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
nvdv4.01.9LOWCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.04.3MEDIUMAV:L/AC:L/Au:S/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
A vulnerability was determined in GNU LibreDWG 0.13.4-154-g0b573035.
ghsa_unreviewed·2026-07-13
CVE-2026-15520 [LOW] CWE-119 A vulnerability was determined in GNU LibreDWG 0.13.4-154-g0b573035.
A vulnerability was determined in GNU LibreDWG 0.13.4-154-g0b573035. This impacts the function decompress_R2004_section of the file src/decode.c of the component R2004 Section Decompression. Executing a manipulation can lead to heap-based buffer overflow. The attack requires local access. The exploit has been publicly disclosed and may be utilized. Upgrading to version 0.14.8396 will fix this issue. This patch is called 3d0f9fc2eddbd6579c99af3111c37c98f03475d0. You should upgrade the affected component.
VulDB
GNU LibreDWG 0.13.4-154-g0b573035 R2004 Section Decompression src/decode.c decompress_R2004_section heap-based overflow (Issue 1251)
vuldb·2026-07-12
CVE-2026-15520 [CRITICAL] GNU LibreDWG 0.13.4-154-g0b573035 R2004 Section Decompression src/decode.c decompress_R2004_section heap-based overflow (Issue 1251)
A vulnerability, which was classified as critical, was found in GNU LibreDWG 0.13.4-154-g0b573035. This impacts the function decompress_R2004_section of the file src/decode.c of the component R2004 Section Decompression. Executing a manipulation can lead to heap-based buffer overflow.
This vulnerability appears as CVE-2026-15520. The attack requires local access. In addition, an exploit is available.
You should upgrade the affected component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/HackC0der/CVE-Repos/blob/main/libredwg/libredwg_0b57303_heap_overflow_decompress_R2004_section.dwghttps://github.com/LibreDWG/libredwg/commit/3d0f9fc2eddbd6579c99af3111c37c98f03475d0https://github.com/LibreDWG/libredwg/issues/1251https://github.com/LibreDWG/libredwg/releases/tag/0.14.8396https://github.com/advisories/GHSA-qg2f-8389-w95jhttps://vuldb.com/cve/CVE-2026-15520https://vuldb.com/submit/851190https://vuldb.com/vuln/377849https://vuldb.com/vuln/377849/ctihttps://www.gnu.org/https://github.com/LibreDWG/libredwg/issues/1251
2026-07-13
Published