CVE-2026-58085
Missing MAC validation in wg(4) packet decryption
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
After dispatching a decrypt operation to OCF and receiving the result, the wg(4) driver failed to check whether the MAC verification step succeeded. The driver thus silently accepted packets with an invalid Poly1305 authentication tag. A remote attacker who can send UDP packets to a WireGuard endpoint, and who can guess the bounds of the receiver's replay window, can inject forged or modified transport data packets into the tunnel. A remote attacker who can intercept WireGuard packets bound for a FreeBSD host can modify the ciphertext and authenticated data without detection by the receiver.
| CWE | CWE-347 |
| Vendor | freebsd |
| Product | freebsd |
| Published | Aug 19, 2026 |
Stay Ahead of the Next One
Get instant alerts for freebsd freebsd
Be the first to know when new unknown vulnerabilities affecting freebsd freebsd are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
FreeBSD / FreeBSD
15.1-RELEASE < p2 15.0-RELEASE < p12 14.4-RELEASE < p8
References
Credits
Reo Shiseki