Description
Freeciv versions 3.1.0 through 3.2.5 contain an out-of-bounds read vulnerability in sg_load_player_unit() when processing savegame files with invalid unit activity indices. An attacker can craft a malicious savegame file with an out-of-range activity index that bypasses bounds checking and causes a crash or limited heap memory exposure when loaded.
Published: 2026-09-12
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Out-of-bounds read causing crash or limited memory disclosure
Action: Patch Immediately
AI Analysis

Impact

An out-of-bounds read occurs in sg_load_player_unit() when Freeciv processes savegame files that contain unit activity indices beyond the allowed range. The improper bounds check can allow a malicious actor to read beyond the intended buffer, potentially exposing a fragment of heap memory or causing the application to terminate. This flaw does not grant direct code execution but can leak sensitive data and interrupt service availability.

Affected Systems

Freeciv releases from version 3.1.0 through 3.2.5 are affected. The vulnerability is present in both the server and client components that load savegame files, so any instance of these products that accepts user-supplied or externally sourced savegames is at risk.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate severity vulnerability. EPSS of less than 1% implies a very low probability of exploitation in the wild at the time of analysis. The flaw is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker can supply a crafted savegame file either by uploading it to a game server or providing it to a local client. Successful exploitation would result in an application crash or a partial memory disclosure, leading primarily to denial of service or limited confidentiality impact.

Generated by OpenCVE AI on September 15, 2026 at 18:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Freeciv to version 3.2.6 or later to apply the fixed bounds checking logic in sg_load_player_unit()
  • Restrict the acceptance of savegame files to trusted users or sources and enforce strict file validation before loading
  • Implement sandboxing or process isolation for the savegame loading routine so that any crash or memory exposure does not compromise the rest of the system

Generated by OpenCVE AI on September 15, 2026 at 18:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 12 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
Description Freeciv versions 3.1.0 through 3.2.5 contain an out-of-bounds read vulnerability in sg_load_player_unit() when processing savegame files with invalid unit activity indices. An attacker can craft a malicious savegame file with an out-of-range activity index that bypasses bounds checking and causes a crash or limited heap memory exposure when loaded.
Title Freeciv 3.1.0 through 3.2.5 Out-of-Bounds Read via Savegame
First Time appeared Freeciv
Freeciv freeciv
Weaknesses CWE-125
CPEs cpe:2.3:a:freeciv:freeciv:*:*:*:*:*:*:*:*
Vendors & Products Freeciv
Freeciv freeciv
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-15T17:08:59.234Z

Reserved: 2026-09-12T11:13:43.326Z

Link: CVE-2026-90557

cve-icon Vulnrichment

Updated: 2026-09-15T17:08:53.852Z

cve-icon NVD

Status : Deferred

Published: 2026-09-12T18:16:44.343

Modified: 2026-09-23T17:17:47.410

Link: CVE-2026-90557

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T18:30:14Z

Weaknesses