Integer Overflow (CWE-190)
CWE-190 describes a calculation that can overflow or wrap around while the logic assumes the result will exceed the original value. When a value grows past what its type can store, it may become very small or negative. MITRE notes that overflow and wraparound are sometimes used interchangeably.
About CWE-190
The undefined behavior commonly causes crashes, and wrong sizes used for allocation can lead to buffer overflows and code execution. Overflow in a loop index can also produce excessive CPU use or altered logic.
Mitigations
- +Validate numeric input against both minimum and maximum expected values.
- +Use safe integer libraries such as SafeInt or IntegerLib.
- +Understand the language's numeric representation, including size, signedness, truncation and 32-bit versus 64-bit differences.
- +Review compiler warnings and fix signed and unsigned mismatches in memory operations.
- +Choose a language or compiler that performs automatic bounds checking.
Detection
Automated static analysis is rated highly effective. Black box fuzzing has moderate effectiveness and may need manual follow-up to confirm the root cause.
CWE-190 Vulnerabilities
7 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2026-21385 | Integer Overflow or Wraparound in Graphics | Qualcomm, Inc. | 7.8 | 1.3% | KEV | 2026-03-02 |
| CVE-2018-14634 | Linux Kernel Integer Overflow Vulnerability | The Linux Foundation | 7.8 | 14.7% | KEV | 2018-09-25 |
| CVE-2025-24985 | Windows Fast FAT File System Driver Remote Code Execution Vulnerability | Microsoft | 7.8 | 3.9% | KEV | 2025-03-11 |
| CVE-2022-0185 | Linux Kernel Heap-Based Buffer Overflow Vulnerability | - | 8.4 | 25.2% | KEV | 2022-02-11 |
| CVE-2024-38080 | Windows Hyper-V Elevation of Privilege Vulnerability | Microsoft | 7.8 | 7.1% | KEV | 2024-07-09 |
| CVE-2023-33107 | Integer Overflow or Wraparound in Graphics Linux | Qualcomm, Inc. | 8.4 | 0.7% | KEV | 2023-12-05 |
| CVE-2023-21823 | Windows Graphics Component Remote Code Execution Vulnerability | Microsoft | 7.8 | 5.6% | KEV | 2023-02-14 |
Most Affected Vendors
Tool Categories That Address This Weakness
Frequently Asked Questions
What is CWE-190?→
CWE-190 is integer overflow or wraparound: arithmetic produces a value too large for its type, and the result wraps to an unexpected small or negative number.
How can integer overflow lead to memory corruption?→
MITRE notes that an overflow used in a size calculation can cause too little memory to be allocated, which then leads to a buffer overflow.
How many exploited vulnerabilities are classified as CWE-190?→
This database lists 7 CVE records mapped to CWE-190 by their CVE Numbering Authority. 7 of them are in the CISA Known Exploited Vulnerabilities catalog. Examples include CVE-2026-21385, CVE-2018-14634, CVE-2025-24985.
Weakness definitions summarized from the CWE List, © The MITRE Corporation, used under the CWE Terms of Use. CWE mappings come from each CVE record's CNA. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.