Back to overview

CVE-2026-13573

LOW Exploitation: PoC
3.3
CVSS 3.1
Description
A vulnerability was found in llvm llvm-project up to 22.1.6. This affects the function llvm::StringMap::insert in the library /lib/IR/ValueSymbolTable.cpp of the component ValueSymbolTable Module. The manipulation results in stack-based buffer overflow. Attacking locally is a requirement. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.

Metadata

CVE ID
CVE-2026-13573
State
PUBLISHED
Assigner
VulDB
Reserved
2026-06-28 18:47 UTC
Published
2026-06-29 14:00 UTC
Last updated
2026-06-29 15:23 UTC
Primary CWE
CWE-121
Stack-based Buffer Overflow
Vendor / Product
llvm / llvm-project
Sources
cve.org  ·  NVD

Severity & Metrics

3.3 LOW CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R
SSVC — CISA Coordinator
Exploitation
PoC
Automatable
no
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
llvm llvm-project 22.1.0, 22.1.1, 22.1.2, 22.1.3 …
Weakness (CWE)
CWESourceDescription
CWE-119 cna Memory Corruption
CWE-121 cna Stack-based Buffer Overflow
CVSS scores (4)
ScoreSeverityVersionSourceVector
4.8 MEDIUM 4.0 cna CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P
3.3 LOW 3.1 cna CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R
3.3 LOW 3.0 cna CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R
1.7 N/D 2.0 cna AV:L/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:ND/RC:UR
References (7)
Back to overview