Kernel Heap Overflow in ZFS Userspace Management by FreeBSD
CVE-2026-49429
Currently unrated
What is CVE-2026-49429?
A local user with delegated 'userused' ZFS permission can exploit a vulnerability in the ZFS_IOC_USERSPACE_MANY ioctl by sending a truncated 64-bit output buffer request. This discrepancy between the kernel's allocation of a 32-bit integer for the output buffer size and the original 64-bit size used as the buffer limit allows the user to potentially trigger a kernel heap overflow, leading to unauthorized privilege escalation.
Affected Version(s)
FreeBSD 15.1-RELEASE
FreeBSD 15.0-RELEASE
FreeBSD 14.4-RELEASE
