CVE-2026-45258
Last modified
CVE-2026-45258 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. dsp_mmap_single() validated the requested mapping by checking the sum of the user-supplied offset and length against the buffer size. This addition could overflow, so that a large offset and length wrapped around and passed the check. EPSS estimates a 0.15% chance of exploitation in the next 30 days.
Description
dsp_mmap_single() validated the requested mapping by checking the sum of the user-supplied offset and length against the buffer size. This addition could overflow, so that a large offset and length wrapped around and passed the check. The offset was then narrowed from 64 to 32 bits when converted to a buffer address, yielding a mapping that extended past the audio buffer into unrelated kernel memory. The /dev/dsp device nodes are world-accessible by default. On a system with an audio device, either issue allows an unprivileged local user to read and write kernel memory, which can be used to escalate privileges, potentially gaining full control of the affected system. At a minimum, an attacker can crash the kernel, resulting in a Denial of Service (DoS).
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Freebsd | Freebsd | 14.3 |
| Freebsd | Freebsd | 14.4 |
| Freebsd | Freebsd | 15.0 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-45258?
How severe is CVE-2026-45258?
How do I fix CVE-2026-45258?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-45252When a fusefs file system implements extended attributes, th…5.5
- CVE-2026-45253ptrace(PT_SC_REMOTE) failed to properly validate parameters …8.4
- CVE-2026-45254In the case of the cap_net service, when a key present in th…6.5
- CVE-2026-45255When bsdinstall or bsdconfig are prompted to scan for nearby…7.5
- CVE-2026-45256When used to deliver a signal to a specific thread, thr_kill…5.5
- CVE-2026-45257The KTLS receive path decrypted each record in place, assumi…7.8
- CVE-2026-45259sigqueue(2) was marked as permitted in capability mode with …6.5
- CVE-2026-4526In EmberZNet v9.0.2 and earlier, malformed global ZCL messag…6.5
- CVE-2026-45260Pimcore is an Open Source Data & Experience Management Platf…8.1
- CVE-2026-45261GitButler is a modern Git-based version control interface fo…9.3
- CVE-2026-45264Nextcloud is an open source content collaboration platform. …4.3
- CVE-2026-45266Nextcloud is an open source content collaboration platform. …3.5
Are you affected by CVE-2026-45258?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
