CVE-2026-90557
Freeciv versions 3.1.0 through 3.2.5 contain an out-of-bounds read vulnerability in sg_load_player_unit() when processing savegame files with invalid unit activity indices. An attacker can craft a malicious savegame file with an out-of-range activity index that bypasses bounds checking and causes a crash or limited heap memory exposure when loaded.
वीकनेस
Freeciv versions 3.1.0 through 3.2.5 contain an out-of-bounds read vulnerability in sg_load_player_unit() when processing savegame files with invalid unit activity indices. An attacker can craft a malicious savegame file with an out-of-range activity index that bypasses bounds checking and causes a crash or limited heap memory exposure when loaded.
संदर्भ
- https://github.com/freeciv/freeciv
- https://github.com/freeciv/freeciv/blob/R3_2_5/server/savegame/savegame2.c#L4282
- https://github.com/freeciv/freeciv/blob/R3_2_5/server/savegame/savegame3.c#L6108
- https://github.com/freeciv/freeciv/commit/ef0c76c2765fe383140eb1a70dbea1228844152e
- https://github.com/freeciv/freeciv/releases/tag/R3_2_6
- https://redmine.freeciv.org/issues/2162
हमलावर से पहले बग आप ढूँढें।
GitHub से साइन इन करें और एक मिनट से भी कम में अपना पहला ऑडिट चलाएँ। फ़्री प्लान के लिए क्रेडिट कार्ड की ज़रूरत नहीं।