Out-of-bounds read in FreeBSD - CVE-2026-58100
Published: September 30, 2026
Vulnerability details
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to an out-of-bounds read in kqueue_fork_copy_knote() when transferring knotes to a child process during fork. A local user can concurrently grow the parent's file descriptor table and register knotes with file descriptor numbers beyond the child table's bounds to escalate privileges.