Description
Freeciv versions before 3.2.6 contain a heap buffer overflow in worklist_load() when processing savegame files with declared worklist lengths exceeding the fixed array bound of 64 elements. Attackers can craft malicious savegame files that write past the entries array into adjacent heap-allocated struct fields, potentially corrupting memory when a user or server operator loads the file.
Published: 2026-09-12
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Memory Corruption
Action: Patch
AI Analysis

Impact

A heap buffer overflow occurs in the worklist_load function of Freeciv when a savegame declares a worklist length larger than the internal 64‑element array. The overflow writes beyond the array into adjacent heap‑allocated fields, corrupting memory and potentially causing crashes, instability, or more severe exploits if the corrupted memory is used for control flow. The weakness is a classic buffer overflow (CWE‑122).

Affected Systems

All releases of Freeciv before version 3.2.6 are vulnerable. The flaw is triggered when the application processes a savegame file and is independent of operating system or hardware. Both client and server installations that accept externally supplied savegames can be affected.

Risk and Exploitability

The CVSS score of 8.5 classifies this as high severity, while the EPSS score of <1% indicates a very low exploitation probability. The vulnerability is not listed in the CISA KE savegame locally or remotely through the server’s savegame loading interface. Due to memory corruption, the effect could range from application crashes to potential privilege escalation if the corrupted memory is used for control flow. The likely attack vector is the savegame file ingestion path; this is inferred from the description and requires local access or the ability to trigger the load operation on a target system.

Generated by OpenCVE AI on September 15, 2026 at 18:00 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Freeciv to version 3.2.6 or newer to address the buffer overflow vulnerability identified as CWE‑122.
  • If an upgrade is not viable, implement input validation that rejects any savegame declaring a worklist longer than 64 elements before calling worklist_load, mitigating the CWE‑122 weakness.
  • As a temporary measure, disable or restrict the ability to load external savegames on all clients and servers until the patch is applied, reducing exposure to the CWE‑122 issue.

Generated by OpenCVE AI on September 15, 2026 at 18:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 12 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
Description Freeciv versions before 3.2.6 contain a heap buffer overflow in worklist_load() when processing savegame files with declared worklist lengths exceeding the fixed array bound of 64 elements. Attackers can craft malicious savegame files that write past the entries array into adjacent heap-allocated struct fields, potentially corrupting memory when a user or server operator loads the file.
Title Freeciv before 3.2.6 Heap Buffer Overflow via worklist_load
First Time appeared Freeciv
Freeciv freeciv
Weaknesses CWE-122
CPEs cpe:2.3:a:freeciv:freeciv:*:*:*:*:*:*:*:*
Vendors & Products Freeciv
Freeciv freeciv
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-18T17:23:06.892Z

Reserved: 2026-09-12T11:13:43.326Z

Link: CVE-2026-90556

cve-icon Vulnrichment

Updated: 2026-09-18T17:17:14.837Z

cve-icon NVD

Status : Deferred

Published: 2026-09-12T18:16:44.193

Modified: 2026-09-23T17:17:44.267

Link: CVE-2026-90556

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T18:00:17Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow