← Volver al buscador de CVEs

CVE-2026-58090

FreeBSD

Descripción

The SOCK_STREAM receive path in the unix socket implementation failed to fully detach control messages from the socket buffer before processing them. Some error paths would free those messages, leaving freed data mbufs in the receive socket buffer. An unprivileged local user can exploit this use-after-free to escalate privileges.

CVSS 7.8EPSS 0.134%Riesgo 0.79
Ver fuente
Publicación
2026-08-26 05:18:12
Versiones afectadas
unknown
Tipo
Sistema operativo
Última modificación
2026-08-27 04:16:42
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H