Stack Data Exposure in FreeBSD Linux Compatibility Layer
CVE-2026-49424

Currently unrated

Key Information:

Vendor

FreeBSD

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-49424?

A vulnerability in the FreeBSD Linux compatibility layer arises from the mismanagement of stack memory during the translation of the siginfo_t struct. This flaw does not zero out the stack memory, leading to the potential exposure of up to 104 bytes of uninitialized kernel stack data to unprivileged users. This data may inadvertently reveal sensitive information, heightening the risk of unauthorized data access.

Affected Version(s)

FreeBSD 15.0-RELEASE

FreeBSD 14.4-RELEASE

FreeBSD 14.3-RELEASE

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Adam Crosser, Praetorian
.