{"id":"ECHO-915c-a579-c425","upstream":["CVE-2026-13574"],"severity":[],"modified":"2026-07-13T15:45:01.813Z","affected":[{"package":{"ecosystem":"Echo","name":"llvm-toolchain-19"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:19.1.7-3"}]}]}],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2026-13574"}],"withdrawn":"2026-07-13T15:45:01.813Z","summary":"Reported (VulDB) heap-based buffer overflow in GCRelocateInst::getBasePtr\nin llvm/lib/IR/IntrinsicInst.cpp (Bitcode File Handler), reachable only\nby locally feeding a crafted bitcode file to LLVM tooling. NVD carries\nthe \"disputed\" tag and notes \"There are still doubts about whether this\nvulnerability truly exists\". The LLVM project explains that the reported\nbehavior is outside its documented security scope and is therefore not\nconsidered a security vulnerability. Reported against llvm-project\n22.1.x; the shipped toolchain is 19.1.7. Debian classifies it as an\nunimportant issue. No code change required.\nhttps://security-tracker.debian.org/tracker/CVE-2026-13574\n"}