Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 3

Количество 3

nvd логотип

CVE-2026-49416

3 месяца назад

The CONS_HISTORY ioctl handler did not adequately validate the requested history size. A large value caused an integer overflow in the buffer size calculation, resulting in a heap allocation smaller than expected. Subsequent initialization of the buffer wrote beyond the end of the allocation. An unprivileged local user with access to a vt(4) device can trigger an out-of-bounds write in the kernel, potentially escalating privileges.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-f3p8-j3ww-gvq7

3 месяца назад

The CONS_HISTORY ioctl handler did not adequately validate the requested history size. A large value caused an integer overflow in the buffer size calculation, resulting in a heap allocation smaller than expected. Subsequent initialization of the buffer wrote beyond the end of the allocation. An unprivileged local user with access to a vt(4) device can trigger an out-of-bounds write in the kernel, potentially escalating privileges.

CVSS3: 7.8
EPSS: Низкий
fstec логотип

BDU:2026-11340

4 месяца назад

Уязвимость обработчика ioctl-запросов CONS_HISTORY ядра операционных систем FreeBSD, позволяющая нарушителю повысить свои привилегии и выполнить произвольный код

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-49416

The CONS_HISTORY ioctl handler did not adequately validate the requested history size. A large value caused an integer overflow in the buffer size calculation, resulting in a heap allocation smaller than expected. Subsequent initialization of the buffer wrote beyond the end of the allocation. An unprivileged local user with access to a vt(4) device can trigger an out-of-bounds write in the kernel, potentially escalating privileges.

CVSS3: 7.8
0%
Низкий
3 месяца назад
github логотип
GHSA-f3p8-j3ww-gvq7

The CONS_HISTORY ioctl handler did not adequately validate the requested history size. A large value caused an integer overflow in the buffer size calculation, resulting in a heap allocation smaller than expected. Subsequent initialization of the buffer wrote beyond the end of the allocation. An unprivileged local user with access to a vt(4) device can trigger an out-of-bounds write in the kernel, potentially escalating privileges.

CVSS3: 7.8
0%
Низкий
3 месяца назад
fstec логотип
BDU:2026-11340

Уязвимость обработчика ioctl-запросов CONS_HISTORY ядра операционных систем FreeBSD, позволяющая нарушителю повысить свои привилегии и выполнить произвольный код

CVSS3: 7.8
0%
Низкий
4 месяца назад

Уязвимостей на страницу