Impact
A vulnerability exists in the llvm‑project up to version 22.1.6 affecting the llvm::StringMap::insert function in ValueSymbolTable.cpp. Executing an insert with crafted data results in a stack-based buffer overflow (CWE‑119, CWE‑120, CWE‑121). Local execution is required, and a public exploit is available. The LLVM project notes that this behavior lies outside its documented security scope and is not officially considered a security vulnerability, leaving the true impact uncertain. A successful overflow could nevertheless cause local code execution or a crash.
Affected Systems
Vendors: llvm. Products: llvm-project (component ValueSymbolTable). Any installation of llvm-project earlier than or equal to release 22.1.6 is susceptible.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate severity. The EPSS score of < 1% indicates a very low probability of exploitation, and the vulnerability is not listed in CISA's KEV catalog. Based on the description, it is inferred that the stack-based buffer overflow could result in local code execution or denial of service through crashes. Local access is required, but a publicly available exploit exists, making it a realistic threat for systems that allow local users to invoke the affected component. The LLVM project’s statement that the issue falls outside its documented security scope and is not officially classified as a security vulnerability may influence how the incident is handled.
OpenCVE Enrichment