Heap-Based Buffer Overflow in LLVM Project's Bitcode File Handler
CVE-2026-13574
Key Information:
- Vendor
Llvm
- Status
- Vendor
- CVE Published:
- 29 June 2026
Badges
What is CVE-2026-13574?
A vulnerability exists in the LLVM llvm-project affecting the Bitcode File Handler, specifically within the GCRelocateInst::getBasePtr function. This issue allows for heap-based buffer overflow, potentially enabling local attackers to exploit the flaw. Despite early reports of the issue to the project maintainers, no resolution has been provided. Exploitation may pose serious risks if left unaddressed, as it allows manipulation of memory, which could lead to unauthorized access or system compromise.
Affected Version(s)
llvm-project 22.1.0
llvm-project 22.1.1
llvm-project 22.1.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
