Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-49428

CVE-2026-49428: FreeBSD Privilege Escalation Vulnerability

CVE-2026-49428 is a privilege escalation flaw in FreeBSD affecting system calls like open(2) and fspacectl(2). Unprivileged users can exploit it to access freed kernel memory and gain elevated privileges.

Updated:

CVE-2026-49428 Overview

CVE-2026-49428 is a kernel memory management flaw in FreeBSD's POSIX shared memory subsystem. Certain system calls, including open(2) with the O_TRUNC flag and fspacectl(2), can incorrectly free memory backing largepage objects. These operations are not permitted on largepage objects, but the kernel implementation fails to enforce that restriction. An unprivileged local user can trigger the flaw to access freed kernel memory. The condition maps to [CWE-915: Improperly Controlled Modification of Dynamically-Determined Object Attributes] and enables local privilege escalation on affected FreeBSD systems.

Critical Impact

An unprivileged local user can abuse the bug to access freed kernel memory, which can be leveraged to escalate privileges to root on affected FreeBSD hosts.

Affected Products

  • FreeBSD operating system (POSIX shared memory subsystem with largepage support)
  • Systems exposing posixshm largepage functionality to unprivileged users
  • Refer to the FreeBSD Security Advisory for specific affected releases

Discovery Timeline

  • 2026-08-19 - CVE-2026-49428 published to NVD
  • 2026-08-20 - Last updated in NVD database

Technical Details for CVE-2026-49428

Vulnerability Analysis

The flaw resides in FreeBSD's POSIX shared memory (posixshm) implementation. Largepage-backed shared memory objects use physically contiguous, hugepage-sized allocations that require distinct lifecycle management from standard shared memory objects. Certain system paths, notably open(2) invoked with O_TRUNC and the fspacectl(2) hole-punching interface, invoke generic freeing logic against these objects. The kernel does not check whether the target object is a largepage object before freeing backing memory. When these operations run against a largepage object, the kernel releases pages while references remain valid, producing a use-after-free condition in kernel memory.

Root Cause

The root cause is a missing validation check in the posixshm code paths. Largepage shared memory objects have restricted semantics: truncation and space control operations are not supported. The implementation neglects to reject these operations and instead executes the general free path. This results in kernel memory being released while the object still holds references, matching the [CWE-915] pattern of improper object attribute handling.

Attack Vector

Exploitation requires local access with the ability to create POSIX shared memory objects. An unprivileged user creates a largepage shared memory object, then invokes open(2) with O_TRUNC or fspacectl(2) against it. The kernel incorrectly frees the backing memory. The attacker then reclaims and manipulates the freed kernel memory through subsequent allocations, corrupting kernel state to elevate privileges. No user interaction is required, and the attack succeeds without special privileges beyond a local shell.

The vulnerability manifests in the largepage-aware code paths of the FreeBSD POSIX shared memory subsystem. See the FreeBSD Security Advisory FreeBSD-SA-26:44.posixshm for the authoritative technical breakdown and patch details.

Detection Methods for CVE-2026-49428

Indicators of Compromise

  • Unexpected kernel panics or page fault traps referencing shm_* or vm_page_* routines in /var/log/messages or dmesg output
  • Unprivileged processes executing shm_open(2) with SHM_LARGEPAGE flags followed by open(2)O_TRUNC or fspacectl(2) calls against the same descriptor
  • Local user processes achieving root privileges without invoking su, sudo, or setuid binaries

Detection Strategies

  • Audit process activity for anomalous sequences of shm_open, ftruncate, and fspacectl system calls originating from non-privileged users
  • Correlate kernel crash dumps and panic events with recent shared memory syscall activity from unprivileged UIDs
  • Monitor for privilege transitions where a process UID changes to 0 without an authorized escalation path

Monitoring Recommendations

  • Enable FreeBSD audit(4) with policies covering shm_open, ftruncate, fspacectl, and process credential changes
  • Forward audit logs and kernel messages to a centralized log platform for correlation and retention
  • Alert on repeated kernel faults from the same user session, which often precede successful kernel exploitation

How to Mitigate CVE-2026-49428

Immediate Actions Required

  • Apply the FreeBSD security patch referenced in FreeBSD-SA-26:44.posixshm to all affected systems
  • Inventory FreeBSD hosts that expose local shell access to untrusted users and prioritize them for patching
  • Restrict local login and code execution on production FreeBSD systems until patches are deployed

Patch Information

FreeBSD has published corrective patches through the FreeBSD Security Advisory FreeBSD-SA-26:44.posixshm. Administrators should update to the fixed release or apply the source patch, rebuild the kernel, and reboot affected systems. Verify the running kernel matches the patched revision after reboot.

Workarounds

  • Disable largepage POSIX shared memory support where it is not required by workloads
  • Constrain local user access on multi-tenant FreeBSD systems using jail(8) or restricted shells until patches are applied
  • Enforce least privilege on interactive user accounts and remove unnecessary local shell access
bash
# Verify FreeBSD kernel version and apply patches via freebsd-update
uname -a
freebsd-update fetch
freebsd-update install
shutdown -r now

# After reboot, confirm the patched kernel is running
uname -r

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.