CVE-2026-3407 PUBLISHED

YosysHQ yosys BLIF File rtlil.h set heap-based overflow

Assigner: VulDB
Reserved: 01.03.2026 Published: 02.03.2026 Updated: 02.03.2026

A vulnerability was determined in YosysHQ yosys up to 0.62. This affects the function Yosys::RTLIL::Const::set of the file kernel/rtlil.h of the component BLIF File Parser. This manipulation causes heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been publicly disclosed and may be utilized. Applying a patch is the recommended action to fix this issue. It appears that the issue is not reproducible all the time.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P
CVSS Score: 4.8

Product Status

Vendor YosysHQ
Product yosys
Versions
  • Version 0.1 is affected
  • Version 0.2 is affected
  • Version 0.3 is affected
  • Version 0.4 is affected
  • Version 0.5 is affected
  • Version 0.6 is affected
  • Version 0.7 is affected
  • Version 0.8 is affected
  • Version 0.9 is affected
  • Version 0.10 is affected
  • Version 0.11 is affected
  • Version 0.12 is affected
  • Version 0.13 is affected
  • Version 0.14 is affected
  • Version 0.15 is affected
  • Version 0.16 is affected
  • Version 0.17 is affected
  • Version 0.18 is affected
  • Version 0.19 is affected
  • Version 0.20 is affected
  • Version 0.21 is affected
  • Version 0.22 is affected
  • Version 0.23 is affected
  • Version 0.24 is affected
  • Version 0.25 is affected
  • Version 0.26 is affected
  • Version 0.27 is affected
  • Version 0.28 is affected
  • Version 0.29 is affected
  • Version 0.30 is affected
  • Version 0.31 is affected
  • Version 0.32 is affected
  • Version 0.33 is affected
  • Version 0.34 is affected
  • Version 0.35 is affected
  • Version 0.36 is affected
  • Version 0.37 is affected
  • Version 0.38 is affected
  • Version 0.39 is affected
  • Version 0.40 is affected
  • Version 0.41 is affected
  • Version 0.42 is affected
  • Version 0.43 is affected
  • Version 0.44 is affected
  • Version 0.45 is affected
  • Version 0.46 is affected
  • Version 0.47 is affected
  • Version 0.48 is affected
  • Version 0.49 is affected
  • Version 0.50 is affected
  • Version 0.51 is affected
  • Version 0.52 is affected
  • Version 0.53 is affected
  • Version 0.54 is affected
  • Version 0.55 is affected
  • Version 0.56 is affected
  • Version 0.57 is affected
  • Version 0.58 is affected
  • Version 0.59 is affected
  • Version 0.60 is affected
  • Version 0.61 is affected
  • Version 0.62 is affected

Credits

  • Oneafter (VulDB User) reporter

References

Problem Types

  • Heap-based Buffer Overflow CWE
  • Memory Corruption CWE