Junglewise Threat Intelligence

CVE-2026-32848: NetBSD opencrypto race condition in cryptodev_op

CVE-2026-32848 · Severity: medium · CVSS 4.7 · Published 2026-05-18

Executive brief

A vulnerability exists in the NetBSD operating system's cryptographic subsystem, which handles data encryption and decryption for applications. A local user can exploit a timing flaw to cause the system to crash or corrupt its internal memory. This could lead to a complete service outage (kernel panic) or potentially allow for further unauthorized system access.

Technical details

A race condition exists in the NetBSD opencrypto framework due to improper synchronization in the cryptodev_op() and cryptof_ioctl() functions. The vulnerability stems from the csession structure embedding mutable per-operation state (such as uio and iovec) directly within the shared session structure without adequate per-session locking after the global cryptodev_mtx is released. A local attacker on an SMP system can concurrently issue CIOCCRYPT and CIOCFSESSION operations or multiple CIOCCRYPT operations on the same session ID. This allows the attacker to trigger a Use-After-Free (UAF) or a double-free condition on kernel heap memory, potentially leading to a kernel panic or local privilege escalation. The issue was addressed in NetBSD source commit ec8451e.

Affected products

  • NetBSD Foundation NetBSD prior to commit ec8451e

Timeline

  • 2026-02-06: disclosed: Initial research published by nasm.re
  • 2026-04-29: patched: Fix committed to NetBSD source tree
  • 2026-05-18: advisory: CVE-2026-32848 published

References