CVE-2026-90557

EUVD-2026-76902
Freeciv versions 3.1.0 through 3.2.5 contain an out-of-bounds read vulnerability in sg_load_player_unit() when processing savegame files with invalid unit activity indices. An attacker can craft a malicious savegame file with an out-of-range activity index that bypasses bounds checking and causes a crash or limited heap memory exposure when loaded.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
VulnCheckCNA
6.1 MEDIUM
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
freecivfreeciv
3.1.0 ≤
𝑥
< 3.2.6
CNA
Debian logo
Debian Releases
Debian Product
Codename
freeciv
bookworm
unimportant
bookworm (security)
unimportant
forky
3.2.6+ds-1
fixed
sid
3.2.6+ds-1
fixed
trixie
unimportant
trixie (security)
unimportant