Out-of-Bounds Read Vulnerability in Freeciv Affected by Malicious Savegame Files
CVE-2026-90557

6.9MEDIUM

Key Information:

Vendor

Freeciv

Status
Vendor
CVE Published:
12 September 2026

What is CVE-2026-90557?

Freeciv versions 3.1.0 through 3.2.5 suffer from an out-of-bounds read vulnerability in the sg_load_player_unit() function. This issue arises when processing savegame files that contain invalid unit activity indices. Malicious actors can exploit this by crafting a specially-designed savegame file, which includes an activity index exceeding defined bounds. Consequently, this could lead to a potential crash or exposure of limited heap memory, compromising the stability and security of the application.

Affected Version(s)

freeciv 3.1.0 < 3.2.6

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tristan Madani
.