UBUNTU-CVE-2026-13573

Advisory lineage Upstream: 1 Downstream: 0
Upstream
Published: 29 Jun 2026, 15:16
Last modified:09 Jul 2026, 17:15

Vulnerability Summary

Overall Risk (default)
low
19/100
CVSS Score
4.8 MEDIUM
4.0 (osv_ubuntu)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

29 Jun 2026, 15:16
Published
Vulnerability first disclosed
09 Jul 2026, 17:15
Last Modified
Vulnerability information updated

Description

A vulnerability was found in llvm llvm-project up to 22.1.6. This affects the function llvm::StringMap::insert in the library /lib/IR/ValueSymbolTable.cpp of the component ValueSymbolTable Module. The manipulation results in stack-based buffer overflow. Attacking locally is a requirement. The exploit has been made public and could be used. The presence of this vulnerability remains uncertain at this time. The LLVM project explains, that the reported behavior is outside its documented security scope and therefore not considered a security vulnerability.

CVSS Metrics

  • v4.0MEDIUMScore: 4.8CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P
  • v3.1LOWScore: 3.3CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Affected Systems

  • ubuntullvm-toolchain-18

    all | all | all | all

  • ubuntullvm-toolchain-19

    all | all | all

  • ubuntullvm-toolchain-21

    all | all

  • ubuntullvm-toolchain-22

    all

References (8)