PT-2026-89875 · Netbsd Foundation · Netbsd

·

CVE-2026-57843

·

Published

2026-09-11

·

Updated

2026-09-11

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
NetBSD contains an information disclosure vulnerability in mm open() within sys/dev/mm.c that allows unprivileged local users to obtain real kernel virtual addresses by opening world-accessible devices such as /dev/null or /dev/zero, which incorrectly receive the PK KMEM process flag. Attackers can exploit this misconfigured flag to bypass the CANSEE KPTR obfuscation mechanism and read kernel virtual addresses for sensitive kernel structures including struct proc, kauth cred, filedesc, and vmspace via sysctl KERN PROC queries.

Fix

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-57843

Affected Products

Netbsd