CVE-2026-13574Disclosure

LOWCVSS 1.9 · LOW

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was determined in llvm llvm-project up to 22.1.6. This impacts the function GCRelocateInst::getBasePtr in the library llvm/lib/IR/IntrinsicInst.cpp of the component Bitcode File Handler. This manipulation causes heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been publicly disclosed and may be utilized. There are still doubts about whether this vulnerability truly exists. The LLVM project explains, that the reported behavior is outside its documented security scope and therefore not considered a security vulnerability.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-122

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-06-29: 2Technical Details · 2026-06-29: 206-29
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • CVE@CVEnew
    General

    CVE-2026-13574 A vulnerability was determined in llvm llvm-project up to 22.1.6. This impacts the function GCRelocateInst::getBasePtr in the library llvm/lib/IR/IntrinsicInst.cpp of… https://www.cve.org/CVERecord?id=CVE-2026-13574

    Post summary

    The text announces CVE-2026-13574 affecting llvm up to version 22.1.6, impacting the GCRelocateInst::getBasePtr function, without providing evidence of exploits, PoC, or mitigation.

    00010904
    57.7K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-13574 A vulnerability was determined in llvm llvm-project up to 22.1.6. This impacts the function GCRelocateInst::getBasePtr in the library llvm/lib/IR/IntrinsicInst.cpp of… https://www.cve.org/CVERecord?id=CVE-2026-13574 ----- Traducción: CVE-2026-13574 Se … http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-13574 affecting LLVM’s GCRelocateInst::getBasePtr function and provides a link to the official CVE record for additional details.

    0000032
    89 followersView on X

Explore more