PT-2026-71933 · Freebsd · Freebsd

·

CVE-2026-49428

·

Published

2026-06-30

·

Updated

2026-09-01

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FreeBSD (affected versions not specified)
Description Insufficient input validation in the implementation of largepage shared memory objects allows an unprivileged local user to access freed kernel memory. This occurs because certain system calls, such as open(2) with the O TRUNC flag set and fspacectl(2), do not verify if the operation is permitted on largepage objects, leading to the incorrect freeing of memory. This flaw can be exploited to escalate privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-11475
CVE-2026-49428

Affected Products

Freebsd