CVE-2026-58089High· 7.8▾ TwilightWhen a process calls execve(2) to execute a setuid or setgid image, hwpmc(4) is supposed to detach PMCs owned by unprivileged processes. An inverted check meant that this scenario was not handled properly. An unprivileged local user wh…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 42.9 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.1%
When a process calls execve(2) to execute a setuid or setgid image, hwpmc(4) is supposed to detach PMCs owned by unprivileged processes. An inverted check meant that this scenario was not handled properly.
An unprivileged local user who has attached PMCs to a process can continue monitoring it after the process executes a setuid or setgid binary, contrary to the intended policy.
freebsd = 14.4freebsd = 15.0freebsd = 15.1Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-58091High· 7.8The implementation of this ioctl attempts to acquire locks on all channels in a sync group
CVE-2026-58090High· 7.8The SOCK_STREAM receive path in the unix socket implementation failed to fully detach control messages from the socket buffer before processing them
CVE-2026-58093High· 7.0The TIOCSCTTY ioctl handler drops the tty lock in order to acquire the process tree lock
CVE-2026-58094High· 7.8The FIOSSHMLPGCNF ioctl(2) operation configures the page size for a largepage shared memory object
CVE-2026-58092High· 8.1In FreeBSD 15.0, the kernel structure used to represent user credentials changed: previously the primary group ID was stored in the first element of the array containing the list of supplementary group IDs, whereas now the primary group …
CVE-2026-58095High· 8.8mp_Enddisc() used incorrect length calculations when formatting endpoint discriminator addresses for display, allowing a received endpoint option to overflow a global result buffer. A malicious PPP peer can crash ppp(8) or potentially e…