CVE-2026-45252
Last modified
CVE-2026-45252 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. When a fusefs file system implements extended attributes, the kernel may send a FUSE_LISTXATTR message to the userspace daemon to retrieve the list of extended attributes for a given file. The FUSE protocol requires the daemon to return a packed list of NUL-terminated strings. EPSS estimates a 0.28% chance of exploitation in the next 30 days.
Description
When a fusefs file system implements extended attributes, the kernel may send a FUSE_LISTXATTR message to the userspace daemon to retrieve the list of extended attributes for a given file. The FUSE protocol requires the daemon to return a packed list of NUL-terminated strings. The fusefs kernel module calls strlen() on this daemon-supplied buffer without first verifying that the entire list is NUL-terminated. If a malicious daemon sends a non-NUL-terminated list, the fusefs kernel module may read beyond the end of one heap-allocated buffer and potentially write beyond the end of a second buffer. A malicious daemon could disclose up to 253 bytes of kernel heap memory, or it could inject up to 250 attacker-controlled bytes into unallocated kernel heap space.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Freebsd | Freebsd | 14.3 |
| Freebsd | Freebsd | 14.4 |
| Freebsd | Freebsd | 15.0 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-45252?
How severe is CVE-2026-45252?
How do I fix CVE-2026-45252?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-45247Mirasvit Full Page Cache Warmer for Magento 2 before version…9.8
- CVE-2026-45248Hedera Guardian through 3.5.1 contains an authentication byp…6.9
- CVE-2026-45249A cross-site scripting (XSS) vulnerability exists in Apache …6.1
- CVE-2026-4525If a Vault auth mount is configured to pass through the "Aut…8.8
- CVE-2026-45250The setcred(2) system call is only available to privileged u…7.8
- CVE-2026-45251A file descriptor can be closed while a thread is blocked in…7.8
- CVE-2026-45253ptrace(PT_SC_REMOTE) failed to properly validate parameters …8.4
- CVE-2026-45254In the case of the cap_net service, when a key present in th…6.5
- CVE-2026-45255When bsdinstall or bsdconfig are prompted to scan for nearby…7.5
- CVE-2026-45256When used to deliver a signal to a specific thread, thr_kill…5.5
- CVE-2026-45257The KTLS receive path decrypted each record in place, assumi…7.8
- CVE-2026-45258dsp_mmap_single() validated the requested mapping by checkin…7.8
Are you affected by CVE-2026-45252?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
