Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

FreeBSD — Vulnerabilities & Security Advisories 152

Browse all 152 CVE security advisories affecting FreeBSD. AI-powered Chinese analysis, POCs, and references for each vulnerability.

FreeBSD is a Unix-like operating system primarily utilized for servers, networking appliances, and embedded systems requiring high stability and performance. Its core architecture emphasizes code quality and security, yet it remains susceptible to historical vulnerabilities including remote code execution, buffer overflows, and privilege escalation flaws. These issues often stem from complex kernel subsystems or network stack implementations. Notable security characteristics include its strict adherence to POSIX standards and a transparent security advisory process managed by the FreeBSD Security Team. While major incidents are relatively rare compared to larger ecosystems, the presence of over one hundred recorded CVEs highlights the ongoing need for rigorous patch management. Administrators must prioritize timely updates to mitigate risks associated with legacy components and ensure the integrity of critical infrastructure relying on this robust, open-source platform.

Top products by FreeBSD: FreeBSD
CVE ID Title CVSS Severity Published
CVE-2026-58094 TOCTOU race in POSIX shared memory large page configuration — FreeBSD CWE-367 - - 2026-08-26
CVE-2026-58093 Kernel use-after-free via tty ioctls — FreeBSD CWE-362 - - 2026-08-26
CVE-2026-58097 ppp(8): missing length validation in mp_SetEnddisc() — FreeBSD CWE-130 - - 2026-08-26
CVE-2026-58096 ppp(8): missing length validation in LcpDecodeConfig() — FreeBSD CWE-130 - - 2026-08-26
CVE-2026-58095 ppp(8): incorrect length calculation in mp_Enddisc() — FreeBSD CWE-122 - - 2026-08-26
CVE-2026-58092 Unauthorized credential switching — FreeBSD CWE-288 - - 2026-08-26
CVE-2026-58091 Kernel use-after-free via the SNDCTL_DSP_SYNCSTART ioctl — FreeBSD CWE-416 - - 2026-08-26
CVE-2026-58090 Use-after-free in unix SOCK_STREAM message handling — FreeBSD CWE-416 - - 2026-08-26
CVE-2026-58089 hwpmc fails to detach PMCs during exec credential transitions — FreeBSD CWE-273 - - 2026-08-26
CVE-2026-58088 Race condition in ELF core dump segment counting — FreeBSD CWE-362 - - 2026-08-19
CVE-2026-58087 Heap out-of-bounds access in semctl(2) — FreeBSD CWE-191 - - 2026-08-19
CVE-2026-58086 ktrace(2) privilege incorrectly validated in jails — FreeBSD CWE-273 - - 2026-08-19
CVE-2026-58085 Missing MAC validation in wg(4) packet decryption — FreeBSD CWE-347 - - 2026-08-19
CVE-2026-58084 Kernel stack disclosure via timer_settime(2) — FreeBSD CWE-908 - - 2026-08-19
CVE-2026-58083 Use-after-free in kqueue copy-on-fork — FreeBSD CWE-416 - - 2026-08-19
CVE-2026-58082 Stack based buffer overflow in iconv(3) — FreeBSD CWE-121 - - 2026-08-19
CVE-2026-58081 Heap based buffer overflow in iconv(3) — FreeBSD CWE-122 - - 2026-08-19
CVE-2026-49425 Kernel stack disclosure in 32-bit compatibility support — FreeBSD CWE-908 - - 2026-08-19
CVE-2026-49424 Kernel stack disclosure in Linux compatibility layer — FreeBSD CWE-908 - - 2026-08-19
CVE-2026-49423 Remote DOS via uninitialized memory access in KTLS receive — FreeBSD CWE-908 - - 2026-08-19
CVE-2026-49426 Incorrect audit records for ptrace(2) syscall requests — FreeBSD CWE-223 - - 2026-08-19
CVE-2026-49428 posixshm: system calls can incorrectly free memory of largepage objects — FreeBSD CWE-915 - - 2026-08-19
CVE-2026-49427 posixshm: largepage shared memory objects not explicitly wired — FreeBSD CWE-826 - - 2026-08-19
CVE-2026-49422 Use-after-free in TCP RACK stack option handler — FreeBSD CWE-416 - - 2026-08-19
CVE-2026-49421 unlinkat(2) ignores AT_RESOLVE_BENEATH flag — FreeBSD CWE-273 - - 2026-08-19
CVE-2026-49420 Buffer overflow in libalias RTSP handler — FreeBSD CWE-121 - - 2026-08-19
CVE-2026-49431 Incorrect user validation in ZFS_IOC_SET_PROP ioctl — FreeBSD CWE-863 - - 2026-08-19
CVE-2026-49430 Kernel heap overflow in ZFS_IOC_RECV_NEW ioctl — FreeBSD CWE-122 - - 2026-08-19
CVE-2026-49429 Kernel heap overflow in ZFS_IOC_USERSPACE_MANY ioctl — FreeBSD CWE-122 - - 2026-08-19
CVE-2026-49415 Local privilege escalation via execve(2) TOCTOU race — FreeBSD CWE-367 - - 2026-08-19

This page lists every published CVE security advisory associated with FreeBSD. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.