Kernel Vulnerability in FreeBSD Affecting Timer Functionality
CVE-2026-58084

Currently unrated

Key Information:

Vendor

FreeBSD

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-58084?

The vulnerability arises from a flaw in the FreeBSD kernel's handling of system timers utilizing CLOCK_TAI. When a POSIX timer is created and the current time is fetched, the absence of a configured TAI offset leads to a failure in retrieving the timer value. Unfortunately, the kernel fails to check for this error, leading to a situation where uninitialized memory from the kernel stack can be copied to user space. This could allow an unprivileged local user to access sensitive information inadvertently stored in that memory space, potentially compromising system security.

Affected Version(s)

FreeBSD 15.1-RELEASE

FreeBSD 15.0-RELEASE

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Hazley Samsudin of GovTech CSG
.