ECHO-915c-a579-c425

See a problem?
Import Source
https://advisory.echohq.com/osv/ECHO-915c-a579-c425.json
JSON Data
https://api.osv.dev/v1/vulns/ECHO-915c-a579-c425
Upstream
Withdrawn
2026-07-13T15:45:01.813Z
Published
2026-06-30T14:02:16.425Z
Modified
2026-07-13T16:30:03.839551436Z
Summary
Reported (VulDB) heap-based buffer overflow in GCRelocateInst::getBasePtr in llvm/lib/IR/IntrinsicInst.cpp (Bitcode File Handler), reachable only by locally feeding a crafted bitcode file to LLVM tooling. NVD carries the "disputed" tag and notes "There are still doubts about whether this vulnerability truly exists". The LLVM project explains that the reported behavior is outside its documented security scope and is therefore not considered a security vulnerability. Reported against llvm-project 22.1.x; the shipped toolchain is 19.1.7. Debian classifies it as an unimportant issue. No code change required. https://security-tracker.debian.org/tracker/CVE-2026-13574
Details
References

Affected packages

Echo / llvm-toolchain-19

Package

Name
llvm-toolchain-19
Purl
pkg:deb/echo/llvm-toolchain-19

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:19.1.7-3

Database specific

source
"https://advisory.echohq.com/osv/ECHO-915c-a579-c425.json"