freeciv vulnerability

Freeciv versions 3.1.0 through 3.2.5 contain an out-of-bounds read vulnerability in sg_load_player_unit() when processing savegame files with invalid unit activity indices. An attacker can craft a malicious savegame file with an out-of-range activity index that bypasses bounds checking and causes a crash or limited heap memory exposure when loaded.

Published 12 Sep 2026Updated 12 Sep 20267 sources
CVSS 6.9

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.