PT-2026-28219 · Unknown+1 · Kgssapi.Ko+2

·

CVE-2026-4747

·

Published

2026-03-26

·

Updated

2026-07-23

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions FreeBSD (affected versions not specified)
Description A stack-based buffer overflow exists in the kgssapi.ko kernel module and the librpcgss sec library. The issue occurs during the validation of RPCSEC GSS data packets, where a routine responsible for checking the packet signature copies data into a stack buffer without verifying if the buffer is sufficiently large. This flaw can be triggered by a malicious client and does not require prior authentication.
In the kernel, this allows an authenticated user to achieve remote code execution (RCE) if they can send packets to the kernel's NFS server while kgssapi.ko is loaded. In userspace, any application that loads librpcgss sec and operates an RPC server is vulnerable to RCE from any client capable of sending packets.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

RCE

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-04973
CVE-2026-4747

Affected Products

Freebsd
Kgssapi.Ko
Librpcgss Sec