Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2026-11343

Опубликовано: 30 июн. 2026
Источник: fstec
CVSS3: 7.8
CVSS2: 6.8
EPSS Низкий

Описание

Уязвимость функции msync(MS_INVALIDATE) операционных систем FreeBSD связана с возможностью использования памяти после освобождения. Эксплуатация уязвимости может позволить нарушителю повысить свои привилегии

Вендор

FreeBSD Project

Наименование ПО

FreeBSD

Версия ПО

до 14.4-STABLE (FreeBSD)
до 15.1-STABLE (FreeBSD)
до 15.1-RELEASE-p1 (FreeBSD)
до 15.0-RELEASE-p11 (FreeBSD)
до 14.4-RELEASE-p7 (FreeBSD)
до 14.3-RELEASE-p16 (FreeBSD)

Тип ПО

Операционная система

Операционные системы и аппаратные платформы

FreeBSD Project FreeBSD до 14.4-STABLE
FreeBSD Project FreeBSD до 15.1-STABLE
FreeBSD Project FreeBSD до 15.1-RELEASE-p1
FreeBSD Project FreeBSD до 15.0-RELEASE-p11
FreeBSD Project FreeBSD до 14.4-RELEASE-p7
FreeBSD Project FreeBSD до 14.3-RELEASE-p16

Уровень опасности уязвимости

Средний уровень опасности (базовая оценка CVSS 2.0 составляет 6,8)
Высокий уровень опасности (базовая оценка CVSS 3.1 составляет 7,8)

Возможные меры по устранению уязвимости

Использование рекомендаций производителя:
https://www.freebsd.org/security/advisories/FreeBSD-SA-26:37.vm.asc

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Данные уточняются

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 21%
0.00286
Низкий

7.8 High

CVSS3

6.8 Medium

CVSS2

Связанные уязвимости

CVSS3: 8.8
nvd
около 1 месяца назад

When msync(MS_INVALIDATE) is called on a mapping of an unmanaged device object, the physical pages in the mapping range are marked invalid but remain in the pager's page list. A subsequent page fault will cause the fault handler to re-insert the page into the object's list. This corrupts the list, and on object destruction the page is freed twice. An unprivileged local user with access to a device that provides memory-mapped I/O can trigger a use-after-free in the kernel, though this is limited to a pool of objects ("fictitious pages") that are never recycled for a different purpose. It may be possible to exploit this to escalate privileges.

CVSS3: 8.8
github
около 1 месяца назад

When msync(MS_INVALIDATE) is called on a mapping of an unmanaged device object, the physical pages in the mapping range are marked invalid but remain in the pager's page list. A subsequent page fault will cause the fault handler to re-insert the page into the object's list. This corrupts the list, and on object destruction the page is freed twice. An unprivileged local user with access to a device that provides memory-mapped I/O can trigger a use-after-free in the kernel, though this is limited to a pool of objects ("fictitious pages") that are never recycled for a different purpose. It may be possible to exploit this to escalate privileges.

EPSS

Процентиль: 21%
0.00286
Низкий

7.8 High

CVSS3

6.8 Medium

CVSS2