lpe

Tag

Cards List
#lpe

CVE-2026-45257: LPE in FreeBSD via kTLS-RX

Lobsters Hottest · 2026-06-11 Cached

A critical local privilege escalation vulnerability in FreeBSD (CVE-2026-45257) allows an unprivileged user to write arbitrary data into the page cache of any readable file, bypassing file permissions and flags, leading to full root compromise. The bug affects default installations of FreeBSD 13.0 and later via unsafe composition of sendfile, KTLS, and in-kernel AES-GCM decryption.

0 favorites 0 likes
#lpe

FatGid - FreeBSD 14.x kernel LPE

Lobsters Hottest · 2026-05-21 Cached

A kernel stack buffer overflow in FreeBSD 14.x's setcred(2) system call allows any unprivileged local user to escalate privileges to root, even with SMAP/SMEP enabled. The bug is not yet fixed in stable branches.

0 favorites 0 likes
← Back to home

Submit Feedback