# CVE-2026-35547

## Summary

- **CVE ID:** CVE-2026-35547
- **Severity:** HIGH
- **CVSS Score:** 8.1 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** CWE-122, CWE-130
- **Published:** Apr 30, 2026
- **Last Modified:** May 1, 2026

## Description

When processing the header of an incoming message, libnv failed to properly validate the message size.

The lack of validation allows a malicious program to write outside the bounds of a heap allocation.  This can trigger a crash or system panic, and it may be possible for an unprivileged user to exploit the bug to elevate their privileges.

## Affected Products

- FreeBSD — FreeBSD (15.0-RELEASE)
- FreeBSD — FreeBSD (14.4-RELEASE)
- FreeBSD — FreeBSD (14.3-RELEASE)
- FreeBSD — FreeBSD (13.5-RELEASE)

## References

- [CNA](https://security.freebsd.org/advisories/FreeBSD-SA-26:17.libnv.asc)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.32%
- **EPSS Percentile:** 24.3

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._