LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-45257

freebsd · freebsd

Published
CVSS7.8
Severityhigh
WeaknessCWE-123
ExploitedNot in CISA KEV

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

The KTLS receive path decrypted each record in place, assuming that the mbufs holding received data were anonymous and safe to modify. This assumption does not hold for data placed on a socket by sendfile(2), which can reference file-backed memory directly through non-anonymous M_EXTPG pages or EXT_SFBUF mbufs. When the sender transmits such data over a loopback connection without enabling KTLS on the transmit side, the file-backed mbufs reach the receiver's decryption path unchanged. Decrypting a record in place then overwrites the backing file's page cache instead of a private copy of the data. An unprivileged local user who can read a file can overwrite its contents with data of their

References

← Back to the CVE Tracker

Our coverage of CVE-2026-45257

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-45257.