Executive brief
A vulnerability exists in the FreeBSD system console driver, which manages the text-based interface used for system administration. An attacker with local access to the system can exploit a flaw in how the console's scrollback history is resized to crash the system or gain elevated administrative privileges. This could allow a standard user to bypass security restrictions and take full control of the server.
Technical details
An integer overflow vulnerability exists in the FreeBSD vt(4) console driver's CONS_HISTORY ioctl handler. The flaw occurs when calculating the buffer size for a requested scrollback history; an attacker can provide a large value that causes the calculation to wrap around, resulting in a heap allocation that is smaller than required. Subsequent initialization of this buffer leads to an out-of-bounds write in kernel memory. A local, unprivileged user with access to a virtual terminal device can leverage this to achieve kernel-mode code execution and privilege escalation. The issue is addressed in FreeBSD 15.0-RELEASE-p10, 14.4-RELEASE-p6, and 14.3-RELEASE-p15.
Affected products
- FreeBSD FreeBSD 15.0-RELEASE before p10, 14.4-RELEASE before p6, 14.3-RELEASE before p15
Timeline
- 2026-06-07: patched: Initial patches committed to stable branches.
- 2026-06-09: advisory: FreeBSD-SA-26:34.vt published.
- 2026-06-27: disclosed: CVE-2026-49416 published to NVD.