CVE-2026-33250 Details
Description
Freeciv21 is a free open source, turn-based, empire-building strategy game. Versions prior to 3.1.1 crash with a stack overflow when receiving specially-crafted packets. A remote attacker can use this to take down any public server. A malicious server can use this to crash the game on the player's machine. Authentication is not needed and, by default, logs do not contain any useful information. All users should upgrade to Freeciv21 version 3.1.1. Running the server behind a firewall can help mitigate the issue for non-public servers. For local games, Freeciv21 restricts connections to the current user and is therefore not affected.
A denial-of-service vulnerability has been identified in Freeciv21, a turn-based strategy game, in versions prior to 3.1.1. The issue arises from the network protocol's handling of compressed 'jumbo' packets, which can be crafted to cause a stack overflow, crashing the server. This vulnerability can be exploited by a remote attacker to take down public servers or, if a malicious server is involved, to crash the game on a player's machine. Notably, no authentication is required, and default logs do not provide useful information about the incident.
Users are advised to upgrade to Freeciv21 version 3.1.1, which addresses this vulnerability by modifying the packet handling to prevent recursion. This patch is available for Freeciv21 on Windows, Mac, Debian, and through the Arch User Repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Mar 24, 2026CISA-ADP
Assessed Mar 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/longturn/freeciv21/commit/ad8e18ca22595529599782b2984bf44df8d69ed6 | [email protected] | Source CodeVendor |
| https://github.com/longturn/freeciv21/releases/tag/v3.1.1 | [email protected] | Release NotesVendor |
| https://github.com/longturn/freeciv21/security/advisories/GHSA-f76g-6w3f-f6r3 | [email protected] | AdvisoryRemedyVendor |
| https://redmine.freeciv.org/issues/1955 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-121 | Stack-based Buffer Overflow | [email protected] |
| CWE-20 | Improper Input Validation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Freeciv21 | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 24, 2026 | New CVE Received | [email protected] |
Volerion