CVE-2026-13573

NameCVE-2026-13573
DescriptionA vulnerability was found in llvm llvm-project up to 22.1.6. This affects the function llvm::StringMap::insert in the library /lib/IR/ValueSymbolTable.cpp of the component ValueSymbolTable Module. The manipulation results in stack-based buffer overflow. Attacking locally is a requirement. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
llvm-toolchain-18 (PTS)trixie1:18.1.8-18vulnerable
sid1:18.1.8-20vulnerable
llvm-toolchain-19 (PTS)bullseye (security)1:19.1.7-3~deb11u1vulnerable
bookworm1:19.1.7-3~deb12u1vulnerable
trixie1:19.1.7-3vulnerable
forky, sid1:19.1.7-22vulnerable
llvm-toolchain-21 (PTS)forky, sid1:21.1.8-7vulnerable
llvm-toolchain-22 (PTS)forky, sid1:22.1.8-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
llvm-toolchain-18source(unstable)(unfixed)unimportant
llvm-toolchain-19source(unstable)(unfixed)unimportant
llvm-toolchain-21source(unstable)(unfixed)unimportant
llvm-toolchain-22source(unstable)(unfixed)unimportant

Notes

https://github.com/llvm/llvm-project/issues/199187
Crash in CLI tool, no security impact

Search for package or bug name: Reporting problems