CVE-2026-13573

NameCVE-2026-13573
DescriptionA vulnerability was found in llvm llvm-project up to 22.1.6. This affects the function llvm::StringMap::insert in the library /lib/IR/ValueSymbolTable.cpp of the component ValueSymbolTable Module. The manipulation results in stack-based buffer overflow. Attacking locally is a requirement. The exploit has been made public and could be used. The presence of this vulnerability remains uncertain at this time. The LLVM project explains, that the reported behavior is outside its documented security scope and therefore not considered a security vulnerability.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
llvm-toolchain-18 (PTS)trixie1:18.1.8-18vulnerable
sid1:18.1.8-20vulnerable
llvm-toolchain-19 (PTS)bullseye (security)1:19.1.7-3~deb11u1vulnerable
bookworm1:19.1.7-3~deb12u1vulnerable
trixie1:19.1.7-3vulnerable
forky, sid1:19.1.7-22vulnerable
llvm-toolchain-21 (PTS)forky, sid1:21.1.8-7vulnerable
llvm-toolchain-22 (PTS)forky, sid1:22.1.8-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
llvm-toolchain-18source(unstable)(unfixed)unimportant
llvm-toolchain-19source(unstable)(unfixed)unimportant
llvm-toolchain-21source(unstable)(unfixed)unimportant
llvm-toolchain-22source(unstable)(unfixed)unimportant

Notes

https://github.com/llvm/llvm-project/issues/199187
Crash in CLI tool, no security impact

Search for package or bug name: Reporting problems