Kernel Heap Overflow in ZFS Userspace Management by FreeBSD
CVE-2026-49429

Currently unrated

Key Information:

Vendor

FreeBSD

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-49429?

A local user with delegated 'userused' ZFS permission can exploit a vulnerability in the ZFS_IOC_USERSPACE_MANY ioctl by sending a truncated 64-bit output buffer request. This discrepancy between the kernel's allocation of a 32-bit integer for the output buffer size and the original 64-bit size used as the buffer limit allows the user to potentially trigger a kernel heap overflow, leading to unauthorized privilege escalation.

Affected Version(s)

FreeBSD 15.1-RELEASE

FreeBSD 15.0-RELEASE

FreeBSD 14.4-RELEASE

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yuxiang Yang, Yizhou Zhao, Ao Wang, Xuewei Feng, Qi Li, and Ke Xu from Tsinghua University using GLM-5.1 from Z.ai
Emmanuel Genier at Quarkslab
.