Skip to main content

About CWE-190

The undefined behavior commonly causes crashes, and wrong sizes used for allocation can lead to buffer overflows and code execution. Overflow in a loop index can also produce excessive CPU use or altered logic.

MITRE name
Integer Overflow or Wraparound
Abstraction
Base: abstract, but detailed enough to infer detection and prevention methods
Status
Stable
Also known as
Overflow, Wraparound, wrap, wrap-around, wrap around

Mitigations

  • +Validate numeric input against both minimum and maximum expected values.
  • +Use safe integer libraries such as SafeInt or IntegerLib.
  • +Understand the language's numeric representation, including size, signedness, truncation and 32-bit versus 64-bit differences.
  • +Review compiler warnings and fix signed and unsigned mismatches in memory operations.
  • +Choose a language or compiler that performs automatic bounds checking.

Detection
Automated static analysis is rated highly effective. Black box fuzzing has moderate effectiveness and may need manual follow-up to confirm the root cause.

CWE-190 Vulnerabilities

7 CVEs
CVETitleVendorCVSSEPSSKEVPublished
CVE-2026-21385
Integer Overflow or Wraparound in Graphics
Qualcomm, Inc.7.81.3%KEV2026-03-02
CVE-2018-14634
Linux Kernel Integer Overflow Vulnerability
The Linux Foundation7.814.7%KEV2018-09-25
CVE-2025-24985
Windows Fast FAT File System Driver Remote Code Execution Vulnerability
Microsoft7.83.9%KEV2025-03-11
CVE-2022-0185
Linux Kernel Heap-Based Buffer Overflow Vulnerability
-8.425.2%KEV2022-02-11
CVE-2024-38080
Windows Hyper-V Elevation of Privilege Vulnerability
Microsoft7.87.1%KEV2024-07-09
CVE-2023-33107
Integer Overflow or Wraparound in Graphics Linux
Qualcomm, Inc.8.40.7%KEV2023-12-05
CVE-2023-21823
Windows Graphics Component Remote Code Execution Vulnerability
Microsoft7.85.6%KEV2023-02-14

Frequently Asked Questions

What is CWE-190?→

CWE-190 is integer overflow or wraparound: arithmetic produces a value too large for its type, and the result wraps to an unexpected small or negative number.

How can integer overflow lead to memory corruption?→

MITRE notes that an overflow used in a size calculation can cause too little memory to be allocated, which then leads to a buffer overflow.

How many exploited vulnerabilities are classified as CWE-190?→

This database lists 7 CVE records mapped to CWE-190 by their CVE Numbering Authority. 7 of them are in the CISA Known Exploited Vulnerabilities catalog. Examples include CVE-2026-21385, CVE-2018-14634, CVE-2025-24985.

Sources

Weakness definitions summarized from the CWE List, © The MITRE Corporation, used under the CWE Terms of Use. CWE mappings come from each CVE record's CNA. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.