Out-of-bounds Write Vulnerability in FreeBSD ELF Core Dump Handling
CVE-2026-58088

Currently unrated

Key Information:

Vendor

FreeBSD

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-58088?

An out-of-bounds write vulnerability exists in the ELF core dump handling of FreeBSD. This issue arises when the system allocates a buffer based on the number of dumpable VM map entries but fails to properly protect against modifications made by a shared process. As a result, an unprivileged local user, by sharing an address space during a core dump, can exploit this flaw to overwrite memory beyond the allocated buffer, potentially enabling privilege escalation and unauthorized access to system resources.

Affected Version(s)

FreeBSD 15.1-RELEASE

FreeBSD 15.0-RELEASE

FreeBSD 14.4-RELEASE

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Maik Muench of Secfault Security
.