CVE-2025-61154: GNU Libredwg

Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.

Heap buffer overflow vulnerability in LibreDWG versions v0.13.3.7571 up to v0.13.3.7835 allows a crafted DWG file to cause a Denial of Service (DoS) via the function decompress_R2004_section at decode.c.

Affected products

  • GNU Libredwg: from 0.13.3.7571, up to and including 0.13.3.7835

Published 2026-03-12. Last modified 2026-06-17.