{"id":"ECHO-8d11-e996-aa3c","upstream":["CVE-2026-13573"],"severity":[],"modified":"2026-07-13T15:45:01.813Z","affected":[{"package":{"ecosystem":"Echo","name":"llvm-toolchain-19"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:19.1.7-3"}]}]}],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2026-13573"}],"withdrawn":"2026-07-13T15:45:01.813Z","summary":"Reported (VulDB) stack-based buffer overflow in llvm::StringMap::insert\nin lib/IR/ValueSymbolTable.cpp (ValueSymbolTable module), reachable only\nby locally feeding crafted IR/input to LLVM tooling. NVD carries the\n\"disputed\" tag and the record notes \"The presence of this vulnerability\nremains uncertain\". The LLVM project explains that the reported behavior\nis outside its documented security scope and is therefore not considered\na security vulnerability (LLVM libraries are not a security boundary for\nuntrusted input). Reported against llvm-project 22.1.x; the shipped\ntoolchain is 19.1.7. Debian classifies it as an unimportant issue. No\ncode change required.\nhttps://security-tracker.debian.org/tracker/CVE-2026-13573\n"}