Buffer overflow in FreeBSD - CVE-2026-58098
Published: September 30, 2026
Vulnerability details
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to improper validation of a semaphore set identifier in semop(2) when waking after waiting for a semaphore condition. A local user can create and destroy semaphore sets in the same table slot while a semop(2) call is blocked to escalate privileges.