Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 29 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 29 Jun 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was found in llvm llvm-project up to 22.1.6. This affects the function llvm::StringMap::insert in the library /lib/IR/ValueSymbolTable.cpp of the component ValueSymbolTable Module. The manipulation results in stack-based buffer overflow. Attacking locally is a requirement. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet. | |
| Title | llvm llvm-project ValueSymbolTable ValueSymbolTable.cpp insert stack-based overflow | |
| First Time appeared |
Llvm
Llvm llvm-project |
|
| Weaknesses | CWE-119 CWE-121 |
|
| CPEs | cpe:2.3:a:llvm:llvm-project:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Llvm
Llvm llvm-project |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-06-29T15:23:24.648Z
Reserved: 2026-06-28T18:47:36.926Z
Link: CVE-2026-13573
Updated: 2026-06-29T15:23:19.394Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-29T16:30:17Z