Privilege Escalation Vulnerability in FreeBSD SUID Binary
CVE-2026-49415

Currently unrated

Key Information:

Vendor

FreeBSD

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-49415?

This vulnerability allows an unprivileged local user to exploit a timing window during the execution of a SUID binary where process credentials are not properly updated before the virtual address space is modified. This can lead to unauthorized access to sensitive memory regions of the target process via procfs or linprocfs. Attackers can leverage this flaw to gain control over the affected system, posing a significant security risk.

Affected Version(s)

FreeBSD 15.1-RELEASE

FreeBSD 15.0-RELEASE

FreeBSD 14.4-RELEASE

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Synacktiv
.