๐Ÿ” CVE Alert

CVE-2026-49416

UNKNOWN 0.0

Integer overflow in vt(4) CONS_HISTORY ioctl

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The CONS_HISTORY ioctl handler did not adequately validate the requested history size. A large value caused an integer overflow in the buffer size calculation, resulting in a heap allocation smaller than expected. Subsequent initialization of the buffer wrote beyond the end of the allocation. An unprivileged local user with access to a vt(4) device can trigger an out-of-bounds write in the kernel, potentially escalating privileges.

CWE CWE-190
Vendor freebsd
Product freebsd
Published Jun 27, 2026
Stay Ahead of the Next One

Get instant alerts for freebsd freebsd

Be the first to know when new unknown vulnerabilities affecting freebsd freebsd are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

FreeBSD / FreeBSD
15.0-RELEASE < p10 14.4-RELEASE < p6 14.3-RELEASE < p15

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
security.freebsd.org: https://security.freebsd.org/advisories/FreeBSD-SA-26:34.vt.asc

Credits

Ed Maste