PT-2026-27072 · Freeciv21 · Freeciv21
Lmoureaux
·
Published
2026-01-01
·
Updated
2026-03-24
·
CVE-2026-33250
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Freeciv21 versions prior to 3.1.1
Description
Freeciv21, a free and open-source turn-based strategy game, is susceptible to a crash caused by a stack overflow when processing specially crafted network packets. This issue allows a remote attacker to disrupt public servers, and a malicious server can crash the game on a player’s machine. The vulnerability does not require authentication. Logs, by default, do not provide helpful information for investigation.
Recommendations
Upgrade to Freeciv21 version 3.1.1.
For non-public servers, running the server behind a firewall can help mitigate the issue.
For local games, Freeciv21 restricts connections to the current user and is therefore not affected.
Exploit
Fix
RCE
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Freeciv21