CVE-2026-49427
Pages belonging to largepage shared memory objects were not explicitly wired. When sendfile(2) transmitted such an object with the SF_NOCACHE flag, it freed the underlying pages after transmission even though existing mappings still referred to them. An unprivileged local user can abuse the bug to access freed kernel memory. This can be exploited to escalate privileges.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.28%
- CWE
- CWE-826
- Published
- 2026-08-19
- Last modified
- 2026-08-20
Affected products
- FreeBSD FreeBSD
- FreeBSD FreeBSD
- FreeBSD FreeBSD
- FreeBSD FreeBSD
Weakness type
Related vulnerabilities
- CVE-2026-33526 — Squid vulnerable to Denial of Service in ICP Request handling
- CVE-2026-32748 — Squid has Denial of Service in ICP Response handling
- CVE-2024-58249 — In wxWidgets before 3.2.7, a crash can be triggered in wxWidgets apps when connections are refused...
- CVE-2025-31115 — XZ has a heap-use-after-free bug in threaded .xz decoder
- CVE-2025-24912 — hostapd fails to process crafted RADIUS packets properly. When hostapd authenticates wi-fi devices...
- CVE-2024-51727 — Ruijie Reyee OS Premature Release of Resource During Expected Lifetime
- CVE-2023-1297 — Consul Cluster Peering can Result in Denial of Service