Junglewise Threat Intelligence

CVE-2026-58090: FreeBSD unix socket use-after-free privilege escalation

CVE-2026-58090 · Severity: high · CVSS 7.8 · Published 2026-08-26

Technologies: Freebsd. Vendors: Freebsd.

Executive brief

FreeBSD's unix domain socket implementation contains a memory management flaw in how it processes control messages over SOCK_STREAM connections. An unprivileged local user can exploit this use-after-free vulnerability to escalate their privileges and potentially gain administrative access to the system.

Technical details

The vulnerability is a use-after-free in the unix SOCK_STREAM receive path where control messages (such as SCM_RIGHTS for file descriptor passing) fail to be fully detached from the socket buffer before processing. Under certain error conditions, the code frees these messages while references remain in the receive buffer, leaving dangling pointers to freed memory (mbufs). A local unprivileged user can trigger this condition and dereference the freed memory to escalate privileges. The vulnerability affects FreeBSD 15.0 and later; patches are available and reboot is required.

Affected products

  • FreeBSD FreeBSD 15.0 and later

Timeline

  • 2026-08-25: disclosed
  • 2026-08-24: patched

References

Related threats