CVE-2026-3407

LOW

YosysHQ yosys <=0.62 - Buffer Overflow

Title source: llm
STIX 2.1

Description

A vulnerability was determined in YosysHQ yosys up to 0.62. This affects the function Yosys::RTLIL::Const::set of the file kernel/rtlil.h of the component BLIF File Parser. This manipulation causes heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been publicly disclosed and may be utilized. Applying a patch is the recommended action to fix this issue. It appears that the issue is not reproducible all the time.

Scores

CVSS v3 3.3
EPSS 0.0002
EPSS Percentile 4.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-119 CWE-122
Status published
Products (50)
YosysHQ/yosys 0.1
YosysHQ/yosys 0.10
YosysHQ/yosys 0.11
YosysHQ/yosys 0.12
YosysHQ/yosys 0.13
YosysHQ/yosys 0.14
YosysHQ/yosys 0.15
YosysHQ/yosys 0.16
YosysHQ/yosys 0.17
YosysHQ/yosys 0.18
... and 40 more
Published Mar 02, 2026
Tracked Since Mar 02, 2026