VDB
CVE-2026-13574
CVE-2026-13574
PUBLISHED
CVSS 4.8 MEDIUM
Reported by VulDB · Published June 29, 2026
A vulnerability was determined in llvm llvm-project up to 22.1.6. This impacts the function GCRelocateInst::getBasePtr in the library llvm/lib/IR/IntrinsicInst.cpp of the component Bitcode File Handler. This manipulation causes heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been publicly disclosed and may be utilized. There are still doubts about whether this vulnerability truly exists. The LLVM project explains, that the reported behavior is outside its documented security scope and therefore not considered a security vulnerability.
Risk Scores
CVSS 4.0
4.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| llvm | llvm-project | 22.1.0, 22.1.1, 22.1.2 |
| llvm | llvm-project | 22.1.0, 22.1.1, 22.1.2 |
Timeline
- Jun 29, 2026 CVE Published
- Jun 30, 2026 EPSS Score
- Jun 30, 2026 Coalition ESS Score
- Jul 1, 2026 CVE Updated
- Aug 24, 2026 EPSS Score
References
- VDB-374582 | llvm llvm-project Bitcode File IntrinsicInst.cpp getBasePtr heap-based overflow vdb-entrytechnical-description
- VDB-374582 | CTI Indicators (IOB, IOC, IOA) signaturepermissions-required
- CVE-2026-13574 | CVE Analysis and Report third-party-advisory
- Submit #844468 | LLVM LLVM Project commit 3b3a3c2 Heap-based Buffer Overflow third-party-advisory
- issue-tracking
- broken-linkexploit
- product