CVE-2026-45258
FreeBSD FreeBSD, freebsd
dsp_mmap_single() validated the requested mapping by checking the sum of the user-supplied offset and length against the buffer size. This addition could overflow, so that a large offset and length wrapped around and passed the check. The offset was then narrowed from 64 to 32 bits when converted to a buffer address, yielding a mapping that extended past the audio buffer into unrelated kernel memory. The /dev/dsp device nodes are world-accessible by default. On a system with an audio device, either issue allows an unprivileged local user to read and write kernel memory, which can be used to...
- CVSS
- 7.8
- EPSS
- 0.15% 4.78% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.27