PatchSiren

freeciv CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH freeciv CVE published 2026-09-12

CVE-2026-90556

CVE-2026-90556 is a heap buffer overflow vulnerability in Freeciv versions before 3.2.6. The vulnerability occurs in the worklist_load() function when processing savegame files with declared worklist lengths exceeding the fixed array bound of 64 elements. This could potentially allow attackers to craft malicious savegame files that write past the entries array into adjacent heap-allocated struct fields, c [truncated]