๐Ÿ” CVE Alert

CVE-2026-58094

UNKNOWN 0.0

TOCTOU race in POSIX shared memory large page configuration

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The FIOSSHMLPGCNF ioctl(2) operation configures the page size for a largepage shared memory object. This is intended to be used immediately after creating the object, before any memory is allocated for the object. The handler checked whether a page size had already been configured without holding the rangelock. Two concurrent callers could both observe an unconfigured object and set conflicting page sizes, leaving the object in an inconsistent state. An unprivileged local user can exploit this race to escalate privileges.

CWE CWE-367
Vendor freebsd
Product freebsd
Published Aug 26, 2026
Stay Ahead of the Next One

Get instant alerts for freebsd freebsd

Be the first to know when new unknown vulnerabilities affecting freebsd freebsd are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

FreeBSD / FreeBSD
15.1-RELEASE < p3 15.0-RELEASE < p13 14.4-RELEASE < p9

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
security.freebsd.org: https://security.freebsd.org/advisories/FreeBSD-SA-26:63.posixshm.asc

Credits

tsune of GMO Cybersecurity by Ierae, Inc. working with TrendAI Zero Day Initiative