{"id":"openSUSE-SU-2026:21346-1","summary":"Security update for libredwg","details":"This update for libredwg fixes the following issues:\n\nChanges in libredwg:\n\n- Update to snapshot 0.14.8413\n  * fix dwg_next_entity NULL pointer dereference\n    [CVE-2026-15184, boo#1271170]\n  * Fix dwg_bmp thumbnail overflow checks\n    [CVE-2026-15181, boo#1271169]\n  * Resolve NULL pointer dereference (SEGV) in match_BLOCK_HEADER\n    [CVE-2026-9529, boo#1266380]\n  * Added DXB (binary DXF) support: dwgwrite/dwgread/dwg2dxf accept\n    DXB input/output, and dxfwrite accepts DXB.\n  * Minor features:\n  * R2007+ split string stream encoding for Header, Classes, and\n    objects.\n  * Added cycle checks in entity link chains.\n  * Added release helpers and improved CI (ODAFileConverter QT6,\n    xvfb-run).\n  * dwgfuzz: show mode with --version.\n\n- update to 0.14:\n  * Write support for r2004 (AC1018) DWG files.  The encoder now\n    produces compressed, encrypted section headers and the\n    LZ77-compressed object data layout required since r2004.\n  * Split large object files (encode, decode) into 2 objects,\n    significantly reducing peak memory usage during compilation\n    and enabling parallel builds to scale better.\n  * dwgadd: handle fields (e.g. layer, ltype, style) can now be\n    set by table-record name in addition to raw handle references.\n    A string value like `line.layer = \"FOO\"` is resolved via\n    dwg_find_tablehandle() at parse time.\n  * Added DXB (binary DXF) support: dwgwrite/dwgread/dwg2dxf\n    accept DXB input/output, and dxfwrite accepts DXB.\n  * R2007+ split string stream encoding for Header, Classes, and\n    objects.\n  * Added cycle checks in entity link chains.  GH #1226.\n  * Added regression tests for decompress_r2007 OOB reads and\n    R2004 section decompression.  Added dwgfilter.test.\n  * Added release helpers and improved CI (ODAFileConverter QT6,\n    xvfb-run).\n  * dwgfuzz: show mode with --version.\n  * API/ABI changes (source-incompatible):\n  * Renamed HEADER/2NDHEADER.is_maint to maint_rel_version.\n  * Renamed PROXY_OBJECT.dwg_versions.\n  * Bumped SO_VERSION to 0:14:0.\n\n- Update to snapshot 0.13.4.8200\n  * Write support for r2004 (AC1018) DWG files. The encoder now\n    produces compressed, encrypted section headers and the\n    LZ77-compressed object data layout required since r2004.\n  * Split large object files (encode, decode) into 2 objects,\n    significantly reducing peak memory usage during compilation and\n    enabling parallel builds to scale better.\n  * dwgadd: handle fields (e.g. layer, ltype, style) can now be set\n    by table-record name in addition to raw handle references. A\n    string value like `line.layer = \"FOO\"` is resolved via\n    dwg_find_tablehandle() at parse time.\n  * Fix decompress_R2004_section buffer overflow\n    [CVE-2026-9501, CVE-2026-9502, CVE-2026-9529, CVE-2026-9530,\n    boo#1266377, boo#1266378, boo#1266380, boo#1266287]\n  * Fix dwg_next_entity NULL pointer dereference\n    [CVE-2026-9503, boo#1266379]\n  * Fix NULL pointer dereferences in DXF output for corrupted DWG\n    input [CVE-2026-9504, boo#1266321]\n  * decode: fix decompression overflow [CVE-2026-9605, boo#1266365]\n","modified":"2026-07-15T18:24:13.820776949Z","published":"2026-07-13T10:19:51Z","related":["CVE-2026-15181","CVE-2026-15184","CVE-2026-9501","CVE-2026-9502","CVE-2026-9503","CVE-2026-9504","CVE-2026-9529","CVE-2026-9530","CVE-2026-9605"],"upstream":["CVE-2026-15181","CVE-2026-15184","CVE-2026-9501","CVE-2026-9502","CVE-2026-9503","CVE-2026-9504","CVE-2026-9529","CVE-2026-9530","CVE-2026-9605"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266287"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266321"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266365"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266377"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266378"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266379"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266380"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271169"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271170"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-15181"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-15184"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-9501"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-9502"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-9503"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-9504"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-9529"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-9530"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-9605"}],"affected":[{"package":{"name":"libredwg","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/libredwg&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.14.8413-bp160.1.1"}]}],"ecosystem_specific":{"binaries":[{"libredwg-devel":"0.14.8413-bp160.1.1","libredwg-tools":"0.14.8413-bp160.1.1","libredwg0":"0.14.8413-bp160.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21346-1.json"}}],"schema_version":"1.7.5"}