CVE-2026-90556

NameCVE-2026-90556
DescriptionFreeciv versions before 3.2.6 contain a heap buffer overflow in worklist_load() when processing savegame files with declared worklist lengths exceeding the fixed array bound of 64 elements. Attackers can craft malicious savegame files that write past the entries array into adjacent heap-allocated struct fields, potentially corrupting memory when a user or server operator loads the file.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
freeciv (PTS)bookworm, bookworm (security)3.0.6-1+deb12u1vulnerable
trixie (security), trixie3.1.4+ds-2+deb13u1vulnerable
forky, sid3.2.6+ds-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
freecivsource(unstable)3.2.6+ds-1

Notes

[trixie] - freeciv <no-dsa> (Minor issue)
https://redmine.freeciv.org/issues/2161

Search for package or bug name: Reporting problems