CVE-2026-90622
A security flaw has been discovered in GNU libredwg 0.13.4. This impacts the function DWG_TABLE of the file src/dwg.spec of the component Layer Encoding. Performing a manipulation results in null pointer dereference. The attack needs to be approached locally. The exploit has been released to the public and may be used for attacks. Upgrading to version 0.14 will fix this issue. The patch is named f5b548c4c1697d66c3dabd0f6a49280a14365a3a. The affected component should be upgraded. The FIELD_HANDLE macro itself is NULL-safe (emits null_handle) - only the two raw zeroing assignments added by 27118c40 ("encode: also disable LAYER.material") dereferenced a NULL material handle; the fix restores the file's existing if (_obj->style) guard convention for material.
What this means for your business
- An attacker can use it only with access to the machine itself, with an ordinary user login, and without anyone at your company clicking anything.
What to do
- 1Ask your IT team or provider whether any of your systems use the affected product.
- 2If you do, follow the vendor's guidance. No patch reference has been published yet.
Not sure if your company is exposed?
Fastnexa’s certified penetration testers can check whether attackers could use this flaw, or others like it, against your websites, apps and network. The full test is free for our first 10 founding clients until 31 December 2026.
Scoring
- CVSS
- 3.3 (v3.1)
- Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L- CVSS v4
- 1.9
- Weakness
- CWE-404
- Assigned by
- cna@vuldb.com
Dates
- Published
- 2026-09-14
- Last modified
- 2026-09-15
- Sources
- NVD
References
- https://github.com/LibreDWG/libredwg/commit/f5b548c4c1697d66c3dabd0f6a49280a14365a3a
- https://github.com/LibreDWG/libredwg/issues/1269
- https://github.com/LibreDWG/libredwg/releases/tag/0.14
- https://github.com/user-attachments/files/28549357/repro.zip
- https://vuldb.com/cve/CVE-2026-90622
- https://vuldb.com/submit/914770
- https://vuldb.com/vuln/403204
- https://vuldb.com/vuln/403204/cti
- https://www.gnu.org/