CVE-2026-49417

HIGH

FreeBSD sound(4) mmap - Use-After-Free Privilege Escalation

Title source: manual
STIX 2.1

Description

Second, the audio buffer backing a mapping could be freed when the device was closed even though the mapping remained valid. The freed memory could then be reused elsewhere while still accessible through the stale mapping. The /dev/dsp device nodes are world-accessible by default. On a system with an audio device, either issue allows an unprivileged local user to read and write kernel memory, which can be used to escalate privileges, potentially gaining full control of the affected system. At a minimum, an attacker can crash the kernel, resulting in a Denial of Service (DoS).

References (1)

Core 1
Core References

Scores

CVSS v3 7.0
EPSS 0.0013
EPSS Percentile 2.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-416
Status published
Products (6)
freebsd/freebsd 14.3 (15 CPE variants)
freebsd/freebsd 14.4 (6 CPE variants)
freebsd/freebsd 15.0 (10 CPE variants)
FreeBSD/FreeBSD 14.3-RELEASE - p15
FreeBSD/FreeBSD 14.4-RELEASE - p6
FreeBSD/FreeBSD 15.0-RELEASE - p10
Published Jun 27, 2026
Tracked Since Jun 27, 2026