Stack Buffer Overflow in libalias Affects FreeBSD
CVE-2026-49420
Currently unrated
What is CVE-2026-49420?
A vulnerability exists in the RTSP handler of libalias where outgoing packets are rewritten into a fixed-length stack buffer without adequate bounds checking. This can lead to a stack buffer overflow, which, when exploited by sending crafted RTSP traffic from within a NAT gateway, may enable an attacker to execute arbitrary code in the kernel or within the natd process, often with root privileges. Organizations relying on FreeBSD systems should take immediate action to mitigate the risks associated with this vulnerability.
Affected Version(s)
FreeBSD 15.1-RELEASE
FreeBSD 15.0-RELEASE
FreeBSD 14.4-RELEASE
