VDB

CVE-2026-13574

CVE-2026-13574 PUBLISHED CVSS 4.8 MEDIUM

Reported by VulDB · Published June 29, 2026

A vulnerability was determined in llvm llvm-project up to 22.1.6. This impacts the function GCRelocateInst::getBasePtr in the library llvm/lib/IR/IntrinsicInst.cpp of the component Bitcode File Handler. This manipulation causes heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been publicly disclosed and may be utilized. There are still doubts about whether this vulnerability truly exists. The LLVM project explains, that the reported behavior is outside its documented security scope and therefore not considered a security vulnerability.

Risk Scores

CVSS 4.0
4.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P

Affected Products

VendorProductVersions
llvmllvm-project22.1.0, 22.1.1, 22.1.2
llvmllvm-project22.1.0, 22.1.1, 22.1.2

Timeline

  • Jun 29, 2026 CVE Published
  • Jun 30, 2026 EPSS Score
  • Jun 30, 2026 Coalition ESS Score
  • Jul 1, 2026 CVE Updated
  • Aug 24, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›