Junglewise Threat Intelligence

CVE-2026-13574: LLVM llvm-project heap buffer overflow in GCRelocateInst::getBasePtr

CVE-2026-13574 · Severity: low · CVSS 3.3 · Published 2026-06-29

Executive brief

A vulnerability exists in the LLVM compiler infrastructure, a widely used set of tools for building software. An attacker with local access to a development or build environment could provide a specially crafted bitcode file that causes the compiler to crash. This could disrupt software development pipelines or automated build systems, though it does not directly risk the theft of sensitive customer data.

Technical details

A heap-based buffer overflow exists in LLVM's Bitcode File Handler within the `GCRelocateInst::getBasePtr` function in `llvm/lib/IR/IntrinsicInst.cpp`. The vulnerability is caused by a lack of bounds checking when accessing operand bundle inputs or statepoint arguments via a raw offset. Specifically, when `getBasePtrIndex()` returns an out-of-bounds value, the code computes an invalid iterator offset (`begin() + index`) and dereferences it. An attacker can exploit this by providing a malformed LLVM IR bitcode file containing a `gc.relocate` intrinsic with an invalid large index. This results in an out-of-bounds read/access, leading to a denial-of-service (crash) of the LLVM tool (e.g., `opt`). As of the advisory date, the project has been informed but a formal patch has not been confirmed.

Affected products

  • llvm llvm-project up to 22.1.6

Timeline

  • 2026-06-29: disclosed: Public disclosure of the vulnerability and PoC exploit.
  • 2026-06-29: advisory

References