Memory Management Vulnerability in FreeBSD Affecting Largepage Objects
CVE-2026-49428
Currently unrated
What is CVE-2026-49428?
A memory management vulnerability in FreeBSD affects system calls involving largepage objects. The issue arises when calls such as open(2) with the O_TRUNC flag and fspacectl(2) fail to verify whether operations are permitted on largepage objects, leading to the potential for memory to be incorrectly freed. This flaw enables an unprivileged local user to exploit the vulnerability, gaining access to freed kernel memory, which can be utilized for privilege escalation purposes.
Affected Version(s)
FreeBSD 15.1-RELEASE
FreeBSD 15.0-RELEASE
FreeBSD 14.4-RELEASE
