LIVE · cybersecurity feed
Live wire
vendor

Freebsd

29 CVEs published in the last four months. Exploited flaws first.

Critical2
High27
Medium0
Exploited (KEV)0

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-580829.8criticalfreebsdThe ISO-2022 encoding module used a stack buffer sized to MB_LEN_MAX (6 bytes) for intermediate character output.17d ago
CVE-2026-580819.8criticalfreebsdSeveral encoding modules, including HZ, UTF-7, VIQR, and ZW, did not properly check the size of the caller-supplie17d ago
CVE-2026-494208.8highfreebsdThe RTSP handler in libalias rewrote outgoing packets into a fixed-length stack buffer without checking whether th17d ago
CVE-2026-494278.8highfreebsdPages belonging to largepage shared memory objects were not explicitly wired.17d ago
CVE-2026-494188.8highfreebsdWhen msync(MS_INVALIDATE) is called on a mapping of an unmanaged device object, the physical pages in the mapping 18d ago
CVE-2026-494198.8highfreebsdWhen the JAIL_AT_DESC flag is specified, kern_jail_set() and kern_jail_get() released the reference to the caller'18d ago
CVE-2026-394618.8highfreebsdlibcasper(3) communicates with helper processes via UNIX domain sockets, and uses the select(2) system call to wai107d ago
CVE-2026-494158.8highfreebsdDuring execve(2) of a SUID binary, the new virtual address space is installed before the process credentials are u18d ago
CVE-2026-452538.4highfreebsdptrace(PT_SC_REMOTE) failed to properly validate parameters for the syscall(2) and __syscall(2) meta-system calls.107d ago
CVE-2026-580838.4highfreebsdWhile the kernel was copying knotes during fork, a knote with a timer-based filter could fire and be enqueued on t17d ago
CVE-2026-494228.4highfreebsdThe RACK setsockopt(2) handler drops the connection lock in order to copy option data from userspace, then reacqui17d ago
CVE-2026-494288.4highfreebsdCertain system calls, such open(2) with the O_TRUNC flag set, and fspacectl(2), could incorrectly free memory in l17d ago
CVE-2026-580868.1highfreebsdAs an inadvertent side effect of an unrelated code change, PRIV_KTRACE was always denied to a jailed root user.17d ago
CVE-2026-452507.8highfreebsdThe setcred(2) system call is only available to privileged users.107d ago
CVE-2026-452517.8highfreebsdA file descriptor can be closed while a thread is blocked in a poll(2) or select(2) call waiting for that descript107d ago
CVE-2026-452577.8highfreebsdThe KTLS receive path decrypted each record in place, assuming that the mbufs holding received data were anonymous71d ago
CVE-2026-494167.8highfreebsdThe CONS_HISTORY ioctl handler did not adequately validate the requested history size.70d ago
CVE-2026-452587.8highfreebsddsp_mmap_single() validated the requested mapping by checking the sum of the user-supplied offset and length again70d ago
CVE-2026-494127.8highfreebsdThe kernel handler for IPV6_MSFILTER dropped a serializing lock in order to copy the source-filter list from users70d ago
CVE-2026-494147.8highfreebsdThe ELF image activator cleared per-process ASLR preference flags for setuid binaries after the code that computes70d ago
CVE-2026-494297.8highfreebsdThe ZFS_IOC_USERSPACE_MANY ioctl, used by zfs-userspace(8), truncated a 64-bit output buffer size to a 32-bit inte17d ago
CVE-2026-494307.8highfreebsdThe ZFS_IOC_RECV_NEW ioctl, in the heal receive path, similarly truncated a 64-bit payload size to a 32-bit intege17d ago
CVE-2026-580877.8highfreebsdThe GETALL and SETALL commands in semctl(2) recorded the number of semaphores in the target set, dropped the lock 17d ago
CVE-2026-580857.5highfreebsdAfter dispatching a decrypt operation to OCF and receiving the result, the wg(4) driver failed to check whether th17d ago
CVE-2026-452557.5highfreebsdWhen bsdinstall or bsdconfig are prompted to scan for nearby Wi-Fi networks, they build up a list of network names107d ago
CVE-2026-580887.4highfreebsdThe ELF core dump code counted the number of dumpable VM map entries, allocated a buffer for the corresponding pro17d ago
CVE-2026-494137.1highfreebsdThe Linuxulator determined whether a binary was set-user-ID or set-group-ID by checking the P_SUGID process flag.70d ago
CVE-2026-494217.1highfreebsdThe kernel function that implements unlinkat(2) and funlinkat(2) validated the AT_RESOLVE_BENEATH flag but failed 17d ago
CVE-2026-494177highfreebsdSecond, the audio buffer backing a mapping could be freed when the device was closed even though the mapping remai70d ago

Filter the full tracker by Freebsd