Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

FreeBSD — Vulnerabilities & Security Advisories 152

Browse all 152 CVE security advisories affecting FreeBSD. AI-powered Chinese analysis, POCs, and references for each vulnerability.

FreeBSD is a Unix-like operating system primarily utilized for servers, networking appliances, and embedded systems requiring high stability and performance. Its core architecture emphasizes code quality and security, yet it remains susceptible to historical vulnerabilities including remote code execution, buffer overflows, and privilege escalation flaws. These issues often stem from complex kernel subsystems or network stack implementations. Notable security characteristics include its strict adherence to POSIX standards and a transparent security advisory process managed by the FreeBSD Security Team. While major incidents are relatively rare compared to larger ecosystems, the presence of over one hundred recorded CVEs highlights the ongoing need for rigorous patch management. Administrators must prioritize timely updates to mitigate risks associated with legacy components and ensure the integrity of critical infrastructure relying on this robust, open-source platform.

Top products by FreeBSD: FreeBSD
CVE ID Title CVSS Severity Published
CVE-2026-49419 Jail reference count underflow — FreeBSD CWE-911 - - 2026-08-19
CVE-2026-49418 Use-after-free in device pager page list — FreeBSD CWE-416 - - 2026-08-19
CVE-2026-49416 Integer overflow in vt(4) CONS_HISTORY ioctl — FreeBSD CWE-190 - - 2026-06-27
CVE-2026-49414 ASLR bypass for setuid executables via procctl(2) — FreeBSD CWE-179 - - 2026-06-27
CVE-2026-49413 Flaw in Linuxulator execution of setugid binaries — FreeBSD CWE-266 - - 2026-06-27
CVE-2026-49412 Use-after-free bug in the IPV6_MSFILTER socket option handler — FreeBSD CWE-416 - - 2026-06-27
CVE-2026-45259 sigqueue(2) missing capability mode restriction — FreeBSD CWE-266 - - 2026-06-27
CVE-2026-45258 Multiple vulnerabilities in the sound(4) mmap path — FreeBSD CWE-125 - - 2026-06-27
CVE-2026-49417 Multiple vulnerabilities in the sound(4) mmap path — FreeBSD CWE-416 - - 2026-06-27
CVE-2026-45257 Arbitrary file overwrite via the KTLS receive path — FreeBSD CWE-123 - - 2026-06-26
CVE-2026-45256 Missing permission check in thr_kill2(2) — FreeBSD CWE-269 - - 2026-06-26
CVE-2026-45254 Incorrect libcap_net limitation list manipulation — FreeBSD CWE-269 - - 2026-05-21
CVE-2026-45255 Remote code execution via installer Wi-Fi access point scans — FreeBSD CWE-78 - - 2026-05-21
CVE-2026-39461 select(2) file descriptor set overflow causes stack overflow — FreeBSD CWE-121 - - 2026-05-21
CVE-2026-45253 Missing validation in ptrace(PT_SC_REMOTE) — FreeBSD CWE-787 - - 2026-05-21
CVE-2026-45252 Heap overflow in FUSE_LISTXATTR — FreeBSD CWE-122 - - 2026-05-21
CVE-2026-45251 Kernel use-after-free via file descriptor syscalls — FreeBSD CWE-416 - - 2026-05-21
CVE-2026-45250 Stack buffer overflow via setcred(2) — FreeBSD CWE-121 - - 2026-05-21
CVE-2026-35547 Heap overflow in libnv — FreeBSD CWE-122 9.8 - 2026-04-30
CVE-2026-39457 Stack overflow via select() file descriptor set overflow — FreeBSD CWE-121 8.4 - 2026-04-30
CVE-2026-42512 Remotely triggerable out-of-bounds heap write in dhclient — FreeBSD CWE-122 9.8 - 2026-04-30
CVE-2026-7164 pf can overflow the stack parsing crafted SCTP packets — FreeBSD CWE-674 7.5 - 2026-04-30
CVE-2026-7270 Local privilege escalation via execve() — FreeBSD CWE-783 7.8 - 2026-04-30
CVE-2026-42511 Remote code execution via malicious DHCP options — FreeBSD CWE-149 8.8 - 2026-04-30
CVE-2026-6386 Missing large page handling in pmap_pkru_update_range() — FreeBSD CWE-269 7.1AI High AI 2026-04-22
CVE-2026-5398 Kernel use-after-free bug in the TIOCNOTTY handler — FreeBSD CWE-416 8.4AI High AI 2026-04-22
CVE-2026-4748 pf silently ignores certain rules — FreeBSD CWE-480 5.3AI Medium AI 2026-04-01
CVE-2026-4747 Remote code execution via RPCSEC_GSS packet validation — FreeBSD CWE-121 8.8 - 2026-03-26
CVE-2026-4652 Remote denial of service via null pointer dereference — FreeBSD CWE-476 7.5 - 2026-03-26
CVE-2026-4247 TCP: remotely exploitable DoS vector (mbuf leak) — FreeBSD CWE-401 7.5 - 2026-03-26

This page lists every published CVE security advisory associated with FreeBSD. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.