Junglewise Threat Intelligence

CVE-2026-58094: FreeBSD POSIX shared memory race condition privilege escalation

CVE-2026-58094 · Severity: high · CVSS 7.8 · Published 2026-08-26

Technologies: Freebsd. Vendors: Freebsd.

Executive brief

FreeBSD's POSIX shared memory module supports large-page shared memory objects for improved performance. A race condition in the configuration of large-page sizes allows an unprivileged local attacker to exploit the timing gap between checking and setting page configuration to achieve local privilege escalation, potentially gaining administrator-level access to the system.

Technical details

The FIOSSHMLPGCNF ioctl(2) operation configures page size for large-page POSIX shared memory objects created via shm_create_largepage(3). The vulnerability is a time-of-check-time-of-use (TOCTOU) race condition: the handler checks whether a page size was already configured without holding the rangelock, allowing two concurrent callers to both observe an unconfigured state and set conflicting page sizes, leaving the object in an inconsistent state. An unprivileged local user can exploit this race condition to corrupt kernel data structures and escalate privileges. Patches are available and have been applied to all supported FreeBSD branches (14.4, 15.0, and 15.1) as of 2026-08-25.

Affected products

  • FreeBSD FreeBSD All supported versions; patches released for 15.1-RELEASE-p3, 15.0-RELEASE-p13, 14.4-RELEASE-p9, and corresponding stable branches

Timeline

  • 2026-08-25: disclosed: FreeBSD Security Advisory SA-26:63 published
  • 2026-08-25: patched: Patches applied to stable/15, releng/15.1, releng/15.0, stable/14, and releng/14.4

References

Related threats