-
CVE-2026-49425
- EPSS 0.15%
- Veröffentlicht 19.08.2026 07:11:21
- Zuletzt bearbeitet 19.08.2026 08:17:12
- CVE-Watchlists
- Unerledigt
Kernel stack disclosure in 32-bit compatibility support
The compat32 kevent() handler translates a 64-bit kevent struct into a stack- declared 32-bit struct. It did not first zero the stack struct. An unprivileged user may observe a small amount of uninitialized kernel stack data, which may contain sensitive information.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerFreeBSD
≫
Produkt
FreeBSD
Default Statusunknown
Version
15.0-RELEASE
Version <
p11
Status
affected
Version
14.4-RELEASE
Version <
p7
Status
affected
Version
14.3-RELEASE
Version <
p16
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.15% | 0.047 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
CWE-908 Use of Uninitialized Resource
The product uses or accesses a resource that has not been initialized.
https://security.freebsd.org/advisories/FreeBSD-SA-26:48.compat32.asc