← Retour à la recherche de CVE

CVE-2026-58090

FreeBSD

Description

The SOCK_STREAM receive path in the unix socket implementation failed to fully detach control messages from the socket buffer before processing them. Some error paths would free those messages, leaving freed data mbufs in the receive socket buffer. An unprivileged local user can exploit this use-after-free to escalate privileges.

CVSS 7.8EPSS 0.134%Risque 0.79
Voir la source
Publication
2026-08-26 05:18:12
Versions concernées
unknown
Type
Système d’exploitation
Dernière modification
2026-08-27 04:16:42
Vecteur
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H