CVE-2026-13574

LOW

llvm llvm-project Bitcode File IntrinsicInst.cpp getBasePtr heap-based overflow

Title source: cna
STIX 2.1

Description

A vulnerability was determined in llvm llvm-project up to 22.1.6. This impacts the function GCRelocateInst::getBasePtr in the library llvm/lib/IR/IntrinsicInst.cpp of the component Bitcode File Handler. This manipulation causes heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been publicly disclosed and may be utilized. There are still doubts about whether this vulnerability truly exists. The LLVM project explains, that the reported behavior is outside its documented security scope and therefore not considered a security vulnerability.

References (7)

Core 7
Core References
Third Party Advisory third-party-advisory
CVE-2026-13574 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-13574
Third Party Advisory third-party-advisory
Submit #844468 | LLVM LLVM Project commit 3b3a3c2 Heap-based Buffer Overflow
https://vuldb.com/submit/844468
Vdb Entry, Technical Description vdb-entry technical-description
VDB-374582 | llvm llvm-project Bitcode File IntrinsicInst.cpp getBasePtr heap-based overflow
https://vuldb.com/vuln/374582
Signature, Permissions Required signature permissions-required
VDB-374582 | CTI Indicators (IOB, IOC, IOA)
https://vuldb.com/vuln/374582/cti

Scores

CVSS v3 3.3
EPSS 0.0012
EPSS Percentile 2.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-119 CWE-122
Status published
Products (7)
llvm/llvm-project 22.1.0
llvm/llvm-project 22.1.1
llvm/llvm-project 22.1.2
llvm/llvm-project 22.1.3
llvm/llvm-project 22.1.4
llvm/llvm-project 22.1.5
llvm/llvm-project 22.1.6
Published Jun 29, 2026
Tracked Since Jun 29, 2026