Stack Buffer Overflow in libalias Affects FreeBSD
CVE-2026-49420

Currently unrated

Key Information:

Vendor

FreeBSD

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-49420?

A vulnerability exists in the RTSP handler of libalias where outgoing packets are rewritten into a fixed-length stack buffer without adequate bounds checking. This can lead to a stack buffer overflow, which, when exploited by sending crafted RTSP traffic from within a NAT gateway, may enable an attacker to execute arbitrary code in the kernel or within the natd process, often with root privileges. Organizations relying on FreeBSD systems should take immediate action to mitigate the risks associated with this vulnerability.

Affected Version(s)

FreeBSD 15.1-RELEASE

FreeBSD 15.0-RELEASE

FreeBSD 14.4-RELEASE

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Atuin - Automated Vulnerability Discovery Engine, Tianchu Chen of Tencent Xuanwu Lab
UC Berkeley Antiproof
Stanislav Fort of Aisle Research
.