CVE-2026-13574: llvm llvm-project Bitcode File IntrinsicInst.cpp getBasePtr heap-based overflow
A vulnerability was determined in llvm llvm-project up to 22.1.6. This impacts the function GCRelocateInst::getBasePtr in the library llvm/lib/IR/IntrinsicInst.cpp of the component Bitcode File Handler. This manipulation causes heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been publicly disclosed and may be utilized. There are still doubts about whether this vulnerability truly exists. The LLVM project explains, that the reported behavior is outside its documented security scope and therefore not considered a security vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13574?
The severity of CVE-2026-13574 is classified as low with a score of 3.3.
How do I fix CVE-2026-13574?
To fix CVE-2026-13574, upgrade to the latest version of LLVM Project llvm-project beyond version 22.1.6.
What type of vulnerability is CVE-2026-13574?
CVE-2026-13574 is classified as a buffer overflow vulnerability.
What is affected by CVE-2026-13574?
CVE-2026-13574 impacts the function GCRelocateInst::getBasePtr in the llvm/lib/IR/IntrinsicInst.cpp of the Bitcode File Handler.
What impact does CVE-2026-13574 pose?
CVE-2026-13574 can lead to a heap-based buffer overflow, which may allow an attacker to execute arbitrary code.