LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-49427

freebsd · freebsd

Published
CVSS8.8
Severityhigh
WeaknessCWE-826
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

Pages belonging to largepage shared memory objects were not explicitly wired. When sendfile(2) transmitted such an object with the SF_NOCACHE flag, it freed the underlying pages after transmission even though existing mappings still referred to them. An unprivileged local user can abuse the bug to access freed kernel memory. This can be exploited to escalate privileges.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-49427

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-49427.