CVE-2026-13574
Public on 2026-06-29
Modified on 2026-07-01
Description
A vulnerability was determined in llvm llvm-project up to 22.1.6. This impacts the function GCRelocateInst::getBasePtr in the library llvm/lib/IR/IntrinsicInst.cpp of the component Bitcode File Handler. This manipulation causes heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
Severity
See what this means
CVSS v3 Base Score
See breakdown
Affected Packages
| Platform | Package | Release Date | Advisory | Status |
|---|---|---|---|---|
| Amazon Linux 2 - Core | llvm | Pending Fix | ||
| Amazon Linux 2023 | llvm | Pending Fix | ||
| Amazon Linux 2 - Core | llvm-private | Pending Fix | ||
| Amazon Linux 2023 | llvm18 | No Fix Planned | ||
| Amazon Linux 2023 | llvm19 | No Fix Planned | ||
| Amazon Linux 2023 | llvm20 | No Fix Planned | ||
| Amazon Linux 2 - Core | llvm7.0 | Pending Fix | ||
| Amazon Linux 2 - Core | mesa-private-llvm | Pending Fix | ||
| Amazon Linux 2 - Core | rust | Not Affected | ||
| Amazon Linux 2023 | rust | Not Affected |
CVSS Scores
| Score Type | Score | Vector | |
|---|---|---|---|
| Amazon Linux | CVSSv3 | 3.3 | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L |