When copying knotes from a parent kqueue to a child, the copy code did not correctly exclude marker knotes (used internally to track list traversal position) before marking them as in-flux and releasing the kqueue lock. If another thread freed a marker while the lock was dropped, the subsequent in-flux decrement operated on freed memory. (CVE-2026-58099) kqueue_fork_copy_knote() indexed into the child's file descriptor table using a knote's file descriptor number without a bounds check. Because the child's table is copied before knotes are transferred, a concurrent thread in the parent could grow the parent's table and register knotes with file descriptor numbers beyond the end of the child's table, causing an out-of-bounds read. (CVE-2026-58100) An unprivileged local user may be able to exploit these races to escalate privileges.