PatchSiren cyber security CVE debrief
CVE-2026-58088 FreeBSD CVE debrief
An unprivileged local user can trigger an out-of-bounds write on the kernel heap by sharing an address space with a process that dumps core, potentially leading to privilege escalation. This vulnerability affects FreeBSD systems, particularly those running versions 14.4, 15.0, and 15.1, and requires immediate attention from system administrators and security teams to assess exposure and prioritize remediation. The vulnerability is caused by the ELF core dump code counting the number of dumpable VM map entries, allocating a buffer for the corresponding program headers, then iterating over the map a second time to populate them. A process sharing the address space via rfork(2) can
- Vendor
- FreeBSD
- Product
- Unknown
- CVSS
- HIGH 7.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-19
- Original CVE updated
- 2026-08-31
- Advisory published
- 2026-08-19
- Advisory updated
- 2026-08-31
Who should care
System administrators and security teams responsible for FreeBSD systems, particularly those running versions 14.4, 15.0, and 15.1, should assess exposure and prioritize remediation. They should verify inventory of FreeBSD systems, check for core dump configurations, and monitor system logs for potential exploitation attempts. Additionally, they should review compensating controls for exposed systems while remediation is scheduled and verified, and track
Why it matters
CVE-2026-58088 is a high-severity vulnerability in the FreeBSD ELF core dump code that can lead to privilege escalation. System administrators and security teams should assess exposure and prioritize remediation for systems running affected versions.
- Potential privilege escalation via out-of-bounds write on kernel heap
- Increased risk of system compromise for unprivileged local users
- Possible denial-of-service or system instability
- Need for verification of affected versions and exposure
Technical summary
The ELF core dump code counted the number of dumpable VM map entries, allocated a buffer for the corresponding program headers, then iterated over the map a second time to populate them. A process sharing the address space via rfork(2) can mutate the map between the two passes, causing the second pass to write program headers past the end of the buffer. This vulnerability can be triggered by an unprivileged local user sharing an address space with a process that dumps core, potentially leading to privilege escalation. The vulnerability affects FreeBSD systems, particularly those running versions 14.4, 15.0, and 15.1.
Defensive priority
High-priority assessment and remediation recommended for systems running FreeBSD 14.4, 15.0, and 15.1.
Recommended defensive actions
- Assess exposure and prioritize remediation for systems running FreeBSD 14.4, 15.0, and 15.1
- Verify inventory of FreeBSD systems and check for core dump configurations
- Monitor system logs for potential exploitation attempts
- Apply vendor patches or updates as available
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The ELF core dump code has a vulnerability where a process sharing the address space via rfork(2) can mutate the map between two passes, causing the second pass to write program headers past the end of the buffer.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-58088 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-58088
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-58088 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-58088
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://security.freebsd.org/advisories/FreeBSD-SA-26:55.elf.asc
[email protected] - Vendor Advisory, Mailing List
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.