{"id":"CVE-2026-57843","title":"NetBSD contains an information disclosure vulnerability in mm_open() within sys/dev/mm.c that allows unprivileged local users to obtain real kernel virtual addresses by opening world-accessible devices such as /dev/null or /dev/zero, whi…","summary":"NetBSD contains an information disclosure vulnerability in mm_open() within sys/dev/mm.c that allows unprivileged local users to obtain real kernel virtual addresses by opening world-accessible devices such as /dev/null or /dev/zero, whi…","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-732"],"vendor":"The NetBSD Foundation","product":"NetBSD","affected":["NetBSD >= 9.0 < 9.5","NetBSD >= 10.0 <= 10.1"],"published":"2026-09-11","updated":"2026-09-18","sourceUpdated":"2026-09-18T18:17:07.627","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-57843","references":[{"url":"https://gnats.netbsd.org/60373","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/netbsd-mm-open-pk-kmem-flag-kernel-pointer-information-disclosure","label":"disclosure@vulncheck.com"}],"tags":["nvd","cve.org"],"epss":0.00101,"epssPercentile":0.01024,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-18T17:12:11.206495Z"},"ingestedAt":"2026-09-11T17:50:33.555Z","slug":"CVE-2026-57843","body":"## Overview\n\nNetBSD contains an information disclosure vulnerability in mm_open() within sys/dev/mm.c that allows unprivileged local users to obtain real kernel virtual addresses by opening world-accessible devices such as /dev/null or /dev/zero, which incorrectly receive the PK_KMEM process flag. Attackers can exploit this misconfigured flag to bypass the CANSEE_KPTR obfuscation mechanism and read kernel virtual addresses for sensitive kernel structures including struct proc, kauth_cred, filedesc, and vmspace via sysctl KERN_PROC queries.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}