Executive brief
A vulnerability in the FreeBSD audio driver allows a standard user to gain full administrative control over the system. The issue exists in the component that manages audio device memory, which is accessible to all users by default. An attacker can exploit this to read or write sensitive system memory, leading to a total system takeover or a complete service crash.
Technical details
An integer overflow vulnerability exists in the FreeBSD sound(4) driver's dsp_mmap_single() function. The function validates user-supplied offset and length values by checking their sum against the buffer size; however, this addition can overflow, bypassing the bounds check. Furthermore, the 64-bit offset is narrowed to 32 bits during conversion to a buffer address, allowing a mapping to extend into unrelated kernel memory. Since /dev/dsp nodes are world-accessible by default, a local unprivileged attacker can exploit this to achieve arbitrary kernel memory read/write, resulting in local privilege escalation (LPE) or a kernel panic. The issue is resolved in FreeBSD 15.0-RELEASE-p10, 14.4-RELEASE-p6, and 14.3-RELEASE-p15.
Affected products
- FreeBSD FreeBSD 15.0-RELEASE before p10, 14.4-RELEASE before p6, 14.3-RELEASE before p15
Timeline
- 2026-06-09: advisory: FreeBSD Project released advisory FreeBSD-SA-26:27.sound
- 2026-06-09: patched
- 2026-06-27: disclosed: NVD publication date