| CVE-2026-58082 | 9.8 | critical | freebsd | The ISO-2022 encoding module used a stack buffer sized to MB_LEN_MAX (6 bytes) for intermediate character output. | 17d ago |
| CVE-2026-58081 | 9.8 | critical | freebsd | Several encoding modules, including HZ, UTF-7, VIQR, and ZW, did not properly check the size of the caller-supplie | 17d ago |
| CVE-2026-49420 | 8.8 | high | freebsd | The RTSP handler in libalias rewrote outgoing packets into a fixed-length stack buffer without checking whether th | 17d ago |
| CVE-2026-49427 | 8.8 | high | freebsd | Pages belonging to largepage shared memory objects were not explicitly wired. | 17d ago |
| CVE-2026-49418 | 8.8 | high | freebsd | When msync(MS_INVALIDATE) is called on a mapping of an unmanaged device object, the physical pages in the mapping | 18d ago |
| CVE-2026-49419 | 8.8 | high | freebsd | When the JAIL_AT_DESC flag is specified, kern_jail_set() and kern_jail_get() released the reference to the caller' | 18d ago |
| CVE-2026-39461 | 8.8 | high | freebsd | libcasper(3) communicates with helper processes via UNIX domain sockets, and uses the select(2) system call to wai | 107d ago |
| CVE-2026-49415 | 8.8 | high | freebsd | During execve(2) of a SUID binary, the new virtual address space is installed before the process credentials are u | 18d ago |
| CVE-2026-45253 | 8.4 | high | freebsd | ptrace(PT_SC_REMOTE) failed to properly validate parameters for the syscall(2) and __syscall(2) meta-system calls. | 107d ago |
| CVE-2026-58083 | 8.4 | high | freebsd | While the kernel was copying knotes during fork, a knote with a timer-based filter could fire and be enqueued on t | 17d ago |
| CVE-2026-49422 | 8.4 | high | freebsd | The RACK setsockopt(2) handler drops the connection lock in order to copy option data from userspace, then reacqui | 17d ago |
| CVE-2026-49428 | 8.4 | high | freebsd | Certain system calls, such open(2) with the O_TRUNC flag set, and fspacectl(2), could incorrectly free memory in l | 17d ago |
| CVE-2026-58086 | 8.1 | high | freebsd | As an inadvertent side effect of an unrelated code change, PRIV_KTRACE was always denied to a jailed root user. | 17d ago |
| CVE-2026-45250 | 7.8 | high | freebsd | The setcred(2) system call is only available to privileged users. | 107d ago |
| CVE-2026-45251 | 7.8 | high | freebsd | A file descriptor can be closed while a thread is blocked in a poll(2) or select(2) call waiting for that descript | 107d ago |
| CVE-2026-45257 | 7.8 | high | freebsd | The KTLS receive path decrypted each record in place, assuming that the mbufs holding received data were anonymous | 71d ago |
| CVE-2026-49416 | 7.8 | high | freebsd | The CONS_HISTORY ioctl handler did not adequately validate the requested history size. | 70d ago |
| CVE-2026-45258 | 7.8 | high | freebsd | dsp_mmap_single() validated the requested mapping by checking the sum of the user-supplied offset and length again | 70d ago |
| CVE-2026-49412 | 7.8 | high | freebsd | The kernel handler for IPV6_MSFILTER dropped a serializing lock in order to copy the source-filter list from users | 70d ago |
| CVE-2026-49414 | 7.8 | high | freebsd | The ELF image activator cleared per-process ASLR preference flags for setuid binaries after the code that computes | 70d ago |
| CVE-2026-49429 | 7.8 | high | freebsd | The ZFS_IOC_USERSPACE_MANY ioctl, used by zfs-userspace(8), truncated a 64-bit output buffer size to a 32-bit inte | 17d ago |
| CVE-2026-49430 | 7.8 | high | freebsd | The ZFS_IOC_RECV_NEW ioctl, in the heal receive path, similarly truncated a 64-bit payload size to a 32-bit intege | 17d ago |
| CVE-2026-58087 | 7.8 | high | freebsd | The GETALL and SETALL commands in semctl(2) recorded the number of semaphores in the target set, dropped the lock | 17d ago |
| CVE-2026-58085 | 7.5 | high | freebsd | After dispatching a decrypt operation to OCF and receiving the result, the wg(4) driver failed to check whether th | 17d ago |
| CVE-2026-45255 | 7.5 | high | freebsd | When bsdinstall or bsdconfig are prompted to scan for nearby Wi-Fi networks, they build up a list of network names | 107d ago |
| CVE-2026-58088 | 7.4 | high | freebsd | The ELF core dump code counted the number of dumpable VM map entries, allocated a buffer for the corresponding pro | 17d ago |
| CVE-2026-49413 | 7.1 | high | freebsd | The Linuxulator determined whether a binary was set-user-ID or set-group-ID by checking the P_SUGID process flag. | 70d ago |
| CVE-2026-49421 | 7.1 | high | freebsd | The kernel function that implements unlinkat(2) and funlinkat(2) validated the AT_RESOLVE_BENEATH flag but failed | 17d ago |
| CVE-2026-49417 | 7 | high | freebsd | Second, the audio buffer backing a mapping could be freed when the device was closed even though the mapping remai | 70d ago |