CVE-2026-32848
MEDIUMNetBSD cryptodev Race Condition Double-Free via cryptodev_op()
Title source: cnaDescription
NetBSD prior to commit ec8451e contains a race condition vulnerability in cryptodev_op() within the opencrypto subsystem that allows local attackers to trigger a double-free condition by concurrently issuing CIOCCRYPT operations on the same session identifier on SMP systems. Attackers can exploit mutable per-operation state embedded in the csession struct to corrupt kernel heap memory.
References (3)
Core 3
Core References
Exploit technical-description
exploit
https://nasm.re/posts/uaf_netbsd_crypto/
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/netbsd-cryptodev-race-condition-double-free-via-cryptodev-op
Scores
CVSS v3
4.7
EPSS
0.0001
EPSS Percentile
1.8%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-362
CWE-415
Status
published
Products (1)
NetBSD/src
< ec8451efc1565516aba9e7047e1a1a1ce7953a2f
Published
May 18, 2026
Tracked Since
May 19, 2026