HIGH
CVE-2026-90556
CVSS
7.8
Description
Freeciv versions before 3.2.6 contain a heap buffer overflow in worklist_load() when processing savegame files with declared worklist lengths exceeding the fixed array bound of 64 elements. Attackers can craft malicious savegame files that write past the entries array into adjacent heap-allocated struct fields, potentially corrupting memory when a user or server operator loads the file.
Weakness (CWE)
CWE-122
Heap-based Buffer Overflow
EPSS Score
0.14%
Probability of exploitation in next 30 days
3.6th percentile
References
https://github.com/freeciv/freeciv
https://github.com/freeciv/freeciv/blob/R3_2_5/server/savegame/savegame2.c#L788
https://github.com/freeciv/freeciv/blob/R3_2_5/server/savegame/savegame3.c#L964
https://github.com/freeciv/freeciv/commit/75ecde3e86ddf2fe775768450e9a290a4f4d4387
https://github.com/freeciv/freeciv/releases/tag/R3_2_6
https://redmine.freeciv.org/issues/2161
https://www.vulncheck.com/advisories/freeciv-before-3.2.6-heap-buffer-overflow-via-worklist-load
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.