PT-2026-71930 · Freebsd · Freebsd

·

CVE-2026-49427

·

Published

2026-06-30

·

Updated

2026-09-01

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FreeBSD (affected versions not specified)
Description An issue exists in the implementation of largepage shared memory objects where pages were not explicitly wired. When the sendfile(2) function transmits such an object using the SF NOCACHE flag, it frees the underlying pages after transmission despite existing mappings still referring to them. This use-after-free condition allows an unprivileged local user to access freed kernel memory, which can be exploited to escalate privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-11472
CVE-2026-49427

Affected Products

Freebsd