Reported (VulDB) heap-based buffer overflow in GCRelocateInst::getBasePtr
in llvm/lib/IR/IntrinsicInst.cpp (Bitcode File Handler), reachable only
by locally feeding a crafted bitcode file to LLVM tooling. NVD carries
the "disputed" tag and notes "There are still doubts about whether this
vulnerability truly exists". The LLVM project explains that the reported
behavior is outside its documented security scope and is therefore not
considered a security vulnerability. Reported against llvm-project
22.1.x; the shipped toolchain is 19.1.7. Debian classifies it as an
unimportant issue. No code change required.
https://security-tracker.debian.org/tracker/CVE-2026-13574