๐Ÿ” CVE Alert

CVE-2026-90557

MEDIUM 6.1

Freeciv 3.1.0 through 3.2.5 Out-of-Bounds Read via Savegame

CVSS Score
6.1
EPSS Score
0.1%
EPSS Percentile
2th

Freeciv versions 3.1.0 through 3.2.5 contain an out-of-bounds read vulnerability in sg_load_player_unit() when processing savegame files with invalid unit activity indices. An attacker can craft a malicious savegame file with an out-of-range activity index that bypasses bounds checking and causes a crash or limited heap memory exposure when loaded.

CWE CWE-125
Vendor freeciv
Product freeciv
Published Sep 12, 2026
Last Updated Sep 15, 2026
Stay Ahead of the Next One

Get instant alerts for freeciv freeciv

Be the first to know when new medium vulnerabilities affecting freeciv freeciv are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
High

Affected Versions

freeciv / freeciv
3.1.0 < 3.2.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/freeciv/freeciv/commit/ef0c76c2765fe383140eb1a70dbea1228844152e github.com: https://github.com/freeciv/freeciv redmine.freeciv.org: https://redmine.freeciv.org/issues/2162 github.com: https://github.com/freeciv/freeciv/blob/R3_2_5/server/savegame/savegame3.c#L6108 github.com: https://github.com/freeciv/freeciv/releases/tag/R3_2_6 github.com: https://github.com/freeciv/freeciv/blob/R3_2_5/server/savegame/savegame2.c#L4282 vulncheck.com: https://www.vulncheck.com/advisories/freeciv-3.1.0-through-3.2.5-out-of-bounds-read-via-savegame

Credits

Tristan Madani