Description
A vulnerability was determined in Dvidelabs flatcc up to 0.6.3. This impacts the function align_order_members of the file src/compiler/semantics.c of the component Duplicate Symbol Handler. This manipulation causes reachable assertion. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Patch name: 8b19ba4e992ebcad7f5970704d1afc5507fa5205. To fix this issue, it is recommended to deploy a patch.
Published: 2026-09-14
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via reachable assertion
Action: Immediate Patch
AI Analysis

Impact

The vulnerability involves a reachable assertion in the align_order_members function of the Duplicate Symbol Handler. An attacker can trigger the assertion with crafted input, causing the compiler or any process using flatcc to abort and terminate, potentially leading to service disruption or code execution depending on the execution context.

Affected Systems

Dvidelabs flatcc versions up to and including 0.6.3 are affected. The issue is fixed by applying patch commit 8b19ba4e992ebcad7f5970704d1afc5507fa5205 or upgrading to a newer flatcc release that includes the fix.

Risk and Exploitability

The CVSS score is 6.9, indicating a moderate severity. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog. The attack. The reachable assertion can lead to a denial of service or potential code execution if the vulnerable flatcc library is used in an exposed compiler service.

Generated by OpenCVE AI on September 15, 2026 at 13:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the patch commit 8b19ba4e992ebcad7f5970704d1afc5507fa5205 to the flatcc source or use a flatcc release that incorporates the fix.
  • Rebuild all projects that link against flatcc with the updated library to ensure the vulnerability is removed from deployed binaries.
  • Restrict or isolate any services that compile code with the affected flatcc version to prevent remote exploitation until the patch is applied.

Generated by OpenCVE AI on September 15, 2026 at 13:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in Dvidelabs flatcc up to 0.6.3. This impacts the function align_order_members of the file src/compiler/semantics.c of the component Duplicate Symbol Handler. This manipulation causes reachable assertion. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Patch name: 8b19ba4e992ebcad7f5970704d1afc5507fa5205. To fix this issue, it is recommended to deploy a patch.
Title Dvidelabs flatcc Duplicate Symbol semantics.c align_order_members assertion
First Time appeared Dvidelabs
Dvidelabs flatcc
Weaknesses CWE-617
CPEs cpe:2.3:a:dvidelabs:flatcc:*:*:*:*:*:*:*:*
Vendors & Products Dvidelabs
Dvidelabs flatcc
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:N/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Dvidelabs Flatcc
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T15:43:54.039Z

Reserved: 2026-09-13T13:01:14.131Z

Link: CVE-2026-90786

cve-icon Vulnrichment

Updated: 2026-09-15T15:43:47.071Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T14:17:19.353

Modified: 2026-09-15T16:17:41.200

Link: CVE-2026-90786

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T19:45:12Z

Weaknesses