CVE-2026-49428 - High Severity Vulnerability
Vulnerable Library - src4.0.4
Library home page: https://github.com/MidnightBSD/src.git
Found in base branches: stable/4.0, master
Vulnerable Source Files (1)
/sys/kern/uipc_shm.c
Vulnerability Details
Certain system calls, such open(2) with the O_TRUNC flag set, and fspacectl(2), could incorrectly free memory in largepage objects. These operations are not permitted on largepage objects, but the implementation did not verify this.
An unprivileged local user can abuse the bug to access freed kernel memory. This can be exploited to escalate privileges.
Publish Date: 2026-08-19
URL: CVE-2026-49428
CVSS 3 Score Details (8.4)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Local
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-08-19
Fix Resolution: https://github.com/freebsd/freebsd-src.git - release/15.1.0-p1,https://github.com/freebsd/freebsd-src.git - release/15.0.0-p11,https://github.com/freebsd/freebsd-src.git - release/14.4.0-p7,https://github.com/freebsd/freebsd-src.git - release/14.3.0-p16
Step up your Open Source Security Game with Mend here
CVE-2026-49428 - High Severity Vulnerability
Library home page: https://github.com/MidnightBSD/src.git
Found in base branches: stable/4.0, master
Certain system calls, such open(2) with the O_TRUNC flag set, and fspacectl(2), could incorrectly free memory in largepage objects. These operations are not permitted on largepage objects, but the implementation did not verify this.
An unprivileged local user can abuse the bug to access freed kernel memory. This can be exploited to escalate privileges.
Publish Date: 2026-08-19
URL: CVE-2026-49428
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Local
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.Type: Upgrade version
Release Date: 2026-08-19
Fix Resolution: https://github.com/freebsd/freebsd-src.git - release/15.1.0-p1,https://github.com/freebsd/freebsd-src.git - release/15.0.0-p11,https://github.com/freebsd/freebsd-src.git - release/14.4.0-p7,https://github.com/freebsd/freebsd-src.git - release/14.3.0-p16
Step up your Open Source Security Game with Mend here