CVE-2026-9529: GNU Libredwg

Low severity, CVSS 3.3. EPSS: 0.2% chance of exploitation in the next 30 days.

A security flaw has been discovered in GNU LibreDWG up to 0.14. The affected element is the function match_BLOCK_HEADER of the file dwggrep.c of the component Dwggrep Utility. Performing a manipulation results in null pointer dereference. The attack requires a local approach. The exploit has been released to the public and may be used for attacks.

Affected products

  • GNU Libredwg: version 0.1 only; version 0.2 only; version 0.3 only; version 0.4 only; version 0.5 only; version 0.6 only; …

Published 2026-05-26. Last modified 2026-07-23.