PT-2026-53064 · Freebsd · Freebsd

·

CVE-2026-49414

·

Published

2026-06-27

·

Updated

2026-07-02

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions The product name cannot be determined (affected versions not specified)
Description The ELF image activator cleared per-process ASLR (Address Space Layout Randomization, a security technique that randomizes memory addresses to prevent exploitation) preference flags for setuid binaries after the PIE (Position Independent Executable) base address was computed. This sequence allowed a user-requested ASLR disable to remain active during the base address selection. An unprivileged local user can disable ASLR for a setuid PIE binary by calling the procctl(2) function before execve(2), which simplifies the exploitation of other memory corruption issues within that binary.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-49414

Affected Products

Freebsd