LLVM is a modestly represented compiler infrastructure and toolchain project with a narrow product portfolio centered on the LLVM compiler framework and its Clang front-end, both widely embedded in development environments, operating systems, and language runtimes. Its vulnerability profile centers on memory-safety and file-handling weaknesses—out-of-bounds reads, buffer overflows, improper memory bounds checks, and link-following issues—that reflect the low-level nature of compiler optimization and code generation. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Llvm over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-29939MEDIUM llvm-project commit a0138390 was discovered to contain a segmentation fault via the component mlir::spirv::TargetEnv::TargetEnv(mlir::spirv::TargetEnvAttr). | May 5, 2023 | 5.5 | 20 | NO | NO |
CVE-2023-29935MEDIUM llvm-project commit a0138390 was discovered to contain an assertion failure at !replacements.count(op) && "operation was already replaced. | May 5, 2023 | 5.5 | 20 | NO | NO |
CVE-2023-26924MEDIUM LLVM a0dab4950 has a segmentation fault in mlir::outlineSingleBlockRegion. NOTE: third parties dispute this because the LLVM security policy excludes "Language front-ends ... for w | Mar 27, 2023 | 5.5 | 20 | NO | NO |
CVE-2023-29941MEDIUM llvm-project commit a0138390 was discovered to contain a segmentation fault via the component matchAndRewriteSortOp<mlir::sparse_tensor::SortOp>(mlir::sparse_tensor::SortOp. | May 5, 2023 | 5.5 | 19 | NO | NO |
CVE-2023-29934MEDIUM llvm-project commit 6c01b5c was discovered to contain a segmentation fault via the component mlir::Type::getDialect(). | May 5, 2023 | 5.5 | 19 | NO | NO |
CVE-2023-29933MEDIUM llvm-project commit bd456297 was discovered to contain a segmentation fault via the component mlir::Block::getArgument. | May 5, 2023 | 5.5 | 19 | NO | NO |
CVE-2023-29932MEDIUM llvm-project commit fdbc55a5 was discovered to contain a segmentation fault via the component mlir::IROperand<mlir::OpOperand. | May 5, 2023 | 5.5 | 19 | NO | NO |
CVE-2023-29942MEDIUM llvm-project commit a0138390 was discovered to contain a segmentation fault via the component mlir::Type::isa<mlir::LLVM::LLVMVoidType. | May 5, 2023 | 5.5 | 16 | NO | NO |
The GetHTMLRunDir function in the scan-build utility in Clang 3.5 and earlier allows local users to obtain sensitive information or overwrite arbitrary files via a symlink attack o | Apr 23, 2014 | 1.9 | 11 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Llvm.
Media articles that mention a CVE ID that affects a product developed by Llvm — matched by CVE ID, not by vendor name.