PT-2026-21884 · Freebsd · Freebsd
Adam Crosser
·
Published
2026-02-24
·
Updated
2026-03-09
·
CVE-2026-3038
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
FreeBSD (affected versions not specified)
Description
The
rtsock msg buffer() function copies sockaddr structures into a sockaddr storage structure on the stack without proper validation of the source sockaddr length. This can lead to a 127-byte stack buffer overflow. The overflow overwrites the stack canary for the rtsock msg buffer() function, causing a kernel panic upon function return. An unprivileged user can crash the kernel by triggering this overflow. While the stack canary provides mitigation, other kernel bugs could potentially allow an attacker to bypass this protection, potentially leading to local privilege escalation.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
LPE
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Freebsd