CVE-2026-49419
- EPSS 0.16%
- Veröffentlicht 19.08.2026 04:32:39
- Zuletzt bearbeitet 01.09.2026 20:20:18
When the JAIL_AT_DESC flag is specified, kern_jail_set() and kern_jail_get() released the reference to the caller's current prison before looking up the jail descriptor. If the descriptor lookup failed, error-handling paths released the same referen...
CVE-2026-49418
- EPSS 0.14%
- Veröffentlicht 19.08.2026 04:14:17
- Zuletzt bearbeitet 01.09.2026 20:20:23
When msync(MS_INVALIDATE) is called on a mapping of an unmanaged device object, the physical pages in the mapping range are marked invalid but remain in the pager's page list. A subsequent page fault will cause the fault handler to re-insert the pag...
CVE-2026-49416
- EPSS 0.11%
- Veröffentlicht 27.06.2026 09:25:12
- Zuletzt bearbeitet 01.07.2026 14:04:11
The CONS_HISTORY ioctl handler did not adequately validate the requested history size. A large value caused an integer overflow in the buffer size calculation, resulting in a heap allocation smaller than expected. Subsequent initialization of the b...
CVE-2026-49414
- EPSS 0.11%
- Veröffentlicht 27.06.2026 09:22:23
- Zuletzt bearbeitet 01.07.2026 14:04:23
The ELF image activator cleared per-process ASLR preference flags for setuid binaries after the code that computes the PIE base address, rather than before. As a result, a user-requested ASLR disable was still in effect at the point where the base a...
CVE-2026-49413
- EPSS 0.15%
- Veröffentlicht 27.06.2026 09:16:24
- Zuletzt bearbeitet 01.07.2026 14:04:37
The Linuxulator determined whether a binary was set-user-ID or set-group-ID by checking the P_SUGID process flag. During execve(2), this flag is not yet set at the point where the auxiliary vector is constructed, so AT_SECURE was incorrectly set to ...
- EPSS 0.13%
- Veröffentlicht 27.06.2026 09:16:24
- Zuletzt bearbeitet 01.07.2026 14:04:31
Second, the audio buffer backing a mapping could be freed when the device was closed even though the mapping remained valid. The freed memory could then be reused elsewhere while still accessible through the stale mapping. The /dev/dsp device nodes...
CVE-2026-49412
- EPSS 0.1%
- Veröffentlicht 27.06.2026 09:16:23
- Zuletzt bearbeitet 01.07.2026 14:04:44
The kernel handler for IPV6_MSFILTER dropped a serializing lock in order to copy the source-filter list from userspace, then reacquired the lock. During this window another thread could free the multicast filter structure, leaving the handler with a...
CVE-2026-45258
- EPSS 0.15%
- Veröffentlicht 27.06.2026 09:16:22
- Zuletzt bearbeitet 01.07.2026 14:04:59
dsp_mmap_single() validated the requested mapping by checking the sum of the user-supplied offset and length against the buffer size. This addition could overflow, so that a large offset and length wrapped around and passed the check. The offset wa...
CVE-2026-45259
- EPSS 0.09%
- Veröffentlicht 27.06.2026 09:16:22
- Zuletzt bearbeitet 01.07.2026 14:04:51
sigqueue(2) was marked as permitted in capability mode with the introduction of Capsicum in 2011, but the implementation of kern_sigqueue did not include a capability mode check restricting signal delivery to the calling process's own PID. A process...
CVE-2026-45257
- EPSS 0.15%
- Veröffentlicht 26.06.2026 14:50:27
- Zuletzt bearbeitet 27.06.2026 05:16:45
The KTLS receive path decrypted each record in place, assuming that the mbufs holding received data were anonymous and safe to modify. This assumption does not hold for data placed on a socket by sendfile(2), which can reference file-backed memory d...