CVE-2026-90557
EUVD-2026-7690212.09.2026, 18:16
Freeciv versions 3.1.0 through 3.2.5 contain an out-of-bounds read vulnerability in sg_load_player_unit() when processing savegame files with invalid unit activity indices. An attacker can craft a malicious savegame file with an out-of-range activity index that bypasses bounds checking and causes a crash or limited heap memory exposure when loaded.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| freeciv | freeciv | 3.1.0 ≤ 𝑥 < 3.2.6 | CNA |
Debian Releases
Common Weakness Enumeration
References