| |
# Summary FreeBSD 14.x contains a critical kernel privilege escalation vulnerability (CVE-2026-45250) in the setcred(2) system call caused by a sizeof type error that creates a stack buffer overflow. Any unprivileged local user can exploit this with a single syscall to gain root access, with working exploits developed for systems with and without SMAP/SMEP protections. Patches have been released for FreeBSD 14.3, 14.4, and 15.0, with users advised to update to the specified patch levels immediately.
Read Full Article →
← More Tech news