Out-of-bounds read in FreeBSD - CVE-2026-58100

 

Out-of-bounds read in FreeBSD - CVE-2026-58100

Published: September 30, 2026


Vulnerability identifier: #VU152950
CSH Severity: Low
CVSS v4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-58100
CWE-ID: CWE-125
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges.

The vulnerability exists due to an out-of-bounds read in kqueue_fork_copy_knote() when transferring knotes to a child process during fork. A local user can concurrently grow the parent's file descriptor table and register knotes with file descriptor numbers beyond the child table's bounds to escalate privileges.


Affected software

FreeBSD

How to mitigate CVE-2026-58100

Install security update from vendor's website.


External References

Related Security Bulletins