CVE-2025-61154: GNU Libredwg
Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.
Heap buffer overflow vulnerability in LibreDWG versions v0.13.3.7571 up to v0.13.3.7835 allows a crafted DWG file to cause a Denial of Service (DoS) via the function decompress_R2004_section at decode.c.
Affected products
- GNU Libredwg: from 0.13.3.7571, up to and including 0.13.3.7835
Published 2026-03-12. Last modified 2026-06-17.