MEDIUMVulnerability
CVE-2026-90557
Freeciv versions 3.1.0 through 3.2.5 contain an out-of-bounds read vulnerability in sg_load_player_unit() when processing savegame files with invalid unit activity indices. An attacker can craft a malicious savegame file with an out-of-range activity index that bypasses bounds checking and causes a crash or limited heap memory exposure when loaded.
Properties
- severity
- MEDIUM
- score
- 6.1
- cve_id
- CVE-2026-90557
- signal_observed_at
- 2026-09-21T23:07:07+00:00
- vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
- published_at
- 2026-09-12T18:16:44.343
- last_modified
- 2026-09-15T18:19:37.057
Related Entities (2)
HAS_WEAKNESS (1)
→[Weakness]Out-of-bounds Read
DESCRIBED_BY (1)
→[Source]NVD
Explore deeper with Ninja Signal's threat intelligence graph