PT-2026-28219 · Unknown+1 · Librpcgss Sec+2

·

CVE-2026-4747

·

Published

2026-03-26

·

Updated

2026-09-06

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions FreeBSD (affected versions not specified)
Description A stack-based buffer overflow exists in the kgssapi.ko kernel module and the librpcgss sec library. The issue occurs during the validation of RPCSEC GSS data packets, where a routine responsible for checking the packet signature copies data into a stack buffer without verifying if the buffer is sufficiently large. This flaw can be triggered by a malicious client and does not require prior authentication.
In the kernel, this allows an authenticated user to achieve remote code execution (RCE) if they can send packets to the kernel's NFS server while kgssapi.ko is loaded. In userspace, any application that loads librpcgss sec and operates an RPC server is vulnerable to RCE from any client capable of sending packets.
Recommendations As a temporary mitigation, restrict access to the kernel's NFS server or avoid loading the kgssapi.ko module if not required. Restrict the use of the librpcgss sec library in userspace applications running RPC servers to minimize the risk of exploitation.

Exploit

Fix

DoS

RCE

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-04973
CVE-2026-4747

Affected Products

Freebsd
Kgssapi.Ko
Librpcgss Sec