Memory Management Vulnerability in FreeBSD Affecting Largepage Objects
CVE-2026-49428

Currently unrated

Key Information:

Vendor

FreeBSD

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-49428?

A memory management vulnerability in FreeBSD affects system calls involving largepage objects. The issue arises when calls such as open(2) with the O_TRUNC flag and fspacectl(2) fail to verify whether operations are permitted on largepage objects, leading to the potential for memory to be incorrectly freed. This flaw enables an unprivileged local user to exploit the vulnerability, gaining access to freed kernel memory, which can be utilized for privilege escalation purposes.

Affected Version(s)

FreeBSD 15.1-RELEASE

FreeBSD 15.0-RELEASE

FreeBSD 14.4-RELEASE

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Chris Jarrett-Davies of the OpenAI Codex Security Team
.