CVE-2026-9500
published 2026-05-25CVE-2026-9500: A vulnerability was found in GNU LibreDWG up to 0.14. The affected element is the function read_2004_compressed_section of the file src/decode.c of the…
PriorityP430medium5.3CVSS 3.1
AVLACLPRLUINSUCLILAL
EPSS
0.12%
2.5th percentile
A vulnerability was found in GNU LibreDWG up to 0.14. The affected element is the function read_2004_compressed_section of the file src/decode.c of the component Dwgread Utility. Performing a manipulation results in heap-based buffer overflow. The attack is only possible with local access. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnu | libredwg | — | — |
| gnu | libredwg | — | — |
| gnu | libredwg | — | — |
| gnu | libredwg | — | — |
| gnu | libredwg | — | — |
| gnu | libredwg | — | — |
| gnu | libredwg | — | — |
| gnu | libredwg | — | — |
| gnu | libredwg | — | — |
| gnu | libredwg | — | — |
| gnu | libredwg | — | — |
| gnu | libredwg | — | — |
| gnu | libredwg | — | — |
| gnu | libredwg | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
nvdv4.01.9LOWCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.04.3MEDIUMAV:L/AC:L/Au:S/C:P/I:P/A:P
cvelistv5v4.04.8MEDIUMCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
vendor_cisco7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hh47-vf3p-8vq5: A vulnerability was found in GNU LibreDWG up to 0
ghsa_unreviewed·2026-05-26
CVE-2026-9500 [LOW] CWE-119 GHSA-hh47-vf3p-8vq5: A vulnerability was found in GNU LibreDWG up to 0
A vulnerability was found in GNU LibreDWG up to 0.14. The affected element is the function read_2004_compressed_section of the file src/decode.c of the component Dwgread Utility. Performing a manipulation results in heap-based buffer overflow. The attack is only possible with local access. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.
CVEList
GNU LibreDWG Dwgread Utility decode.c read_2004_compressed_section heap-based overflow
cvelistv5·2026-05-25·CVSS 4.8
CVE-2026-9500 [MEDIUM] CWE-122 GNU LibreDWG Dwgread Utility decode.c read_2004_compressed_section heap-based overflow
GNU LibreDWG Dwgread Utility decode.c read_2004_compressed_section heap-based overflow
A vulnerability was found in GNU LibreDWG up to 0.14. The affected element is the function read_2004_compressed_section of the file src/decode.c of the component Dwgread Utility. Performing a manipulation results in heap-based buffer overflow. The attack is only possible with local access. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.
Timeline: 2026-05-25: Advisory disclosed; 2026-05-25: VulDB entry created; 2026-05-25: VulDB entry last update
VulDB
GNU LibreDWG up to 0.14 Dwgread Utility src/decode.c read_2004_compressed_section heap-based overflow (Issue 1241 / EUVD-2026-31732)
vuldb·2026-05-25
CVE-2026-9500 [CRITICAL] GNU LibreDWG up to 0.14 Dwgread Utility src/decode.c read_2004_compressed_section heap-based overflow (Issue 1241 / EUVD-2026-31732)
A vulnerability marked as critical has been reported in GNU LibreDWG up to 0.14. The affected element is the function read_2004_compressed_section of the file src/decode.c of the component Dwgread Utility. Performing a manipulation results in heap-based buffer overflow.
This vulnerability is identified as CVE-2026-9500. The attack is only possible with local access. Additionally, an exploit exists.
The project was informed of the problem early through an issue report but has not responded yet.
Cisco
Cisco Nexus 3600 and 9500-R Series Switching Platforms Layer 2 Loop Denial of Service Vulnerability
vendor_cisco·2026-02-25·CVSS 7.4
CVE-2026-20051 [HIGH] CWE-457 Cisco Nexus 3600 and 9500-R Series Switching Platforms Layer 2 Loop Denial of Service Vulnerability
Cisco Nexus 3600 and 9500-R Series Switching Platforms Layer 2 Loop Denial of Service Vulnerability
A vulnerability with the Ethernet VPN (EVPN) Layer 2 ingress packet processing of Cisco Nexus 3600 Platform Switches and Cisco Nexus 9500-R Series Switching Platforms could allow an unauthenticated, adjacent attacker to trigger a Layer 2 traffic loop.
This vulnerability is due to a logic error when processing a crafted Layer 2 ingress frame. An attacker could exploit this vulnerability by sending a stream of crafted Ethernet frames through the targeted device. A successful exploit could allow the attacker to cause a Layer 2 Virtual eXtensible LAN (VxLAN) traffic loop, which, in turn, could result in a denial of service (DoS) condition. This Layer 2 loop could oversubscribe the bandwidth on
Cisco
Cisco Nexus 3600 and 9500-R Series Switching Platforms Layer 2 Loop Denial of Service Vulnerability
vendor_cisco·CVSS 3.1
CVE-2026-20051 Cisco Nexus 3600 and 9500-R Series Switching Platforms Layer 2 Loop Denial of Service Vulnerability
CVE-2026-20051: Cisco Nexus 3600 and 9500-R Series Switching Platforms Layer 2 Loop Denial of Service Vulnerability
A vulnerability with the Ethernet VPN (EVPN) Layer 2 ingress packet processing of Cisco Nexus 3600 Platform Switches and Cisco Nexus 9500-R Series Switching Platforms could allow an unauthenticated, adjacent attacker to trigger a Layer 2 traffic loop. This vulnerability is due to a logic error when processing a crafted Layer 2 ingress frame. An attacker could exploit this vulnerability by sending a stream of crafted Ethernet frames through the targeted device. A successful exploit could allow the attacker to cause a Layer 2 Virtual eXtensible LAN (VxLAN) traffic loop, which, in turn, could result in a denial of service (DoS) condition. This Layer 2 loop could oversubscribe th
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/HackC0der/CVE-Repos/blob/main/libredwg/libredwg_6d6a339_heap_oob_write_read_2004_compressed_section.dwghttps://github.com/LibreDWG/libredwg/issues/1241https://vuldb.com/submit/814248https://vuldb.com/vuln/365482https://vuldb.com/vuln/365482/ctihttps://www.gnu.org/https://github.com/LibreDWG/libredwg/issues/1241
2026-05-25
Published