FreeBSD : FreeBSD -- Memory safety bugs in kqueue copy-on-fork implementation (d725b228-bccc-11f1-906f-bc241121aa0a)

high Nessus Plugin ID 353456

Synopsis

The remote FreeBSD host is missing one or more security-related updates.

Description

The version of FreeBSD installed on the remote host is prior to tested version. It is, therefore, affected by multiple vulnerabilities as referenced in the d725b228-bccc-11f1-906f-bc241121aa0a advisory.

When copying knotes from a parent kqueue to a child, the copy code did not correctly exclude marker knotes (used internally to track list traversal position) before marking them as in-flux and releasing the kqueue lock. If another thread freed a marker while the lock was dropped, the subsequent in-flux decrement operated on freed memory. (CVE-2026-58099) kqueue_fork_copy_knote() indexed into the child's file descriptor table using a knote's file descriptor number without a bounds check.
Because the child's table is copied before knotes are transferred, a concurrent thread in the parent could grow the parent's table and register knotes with file descriptor numbers beyond the end of the child's table, causing an out-of-bounds read. (CVE-2026-58100) An unprivileged local user may be able to exploit these races to escalate privileges.

Tenable has extracted the preceding description block directly from the FreeBSD security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

http://www.nessus.org/u?20708f45

Plugin Details

Severity: High

ID: 353456

File Name: freebsd_pkg_d725b228bccc11f1906fbc241121aa0a.nasl

Version: 1.1

Type: Local

Published: 10/1/2026

Updated: 10/1/2026

Configuration: Enable paranoid mode

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.9

Percentile: 96.5

CVSS v2

Risk Factor: Low

Base Score: 3.6

Temporal Score: 2.7

Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:N/A:P

CVSS Score Source: CVE-2026-58100

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:freebsd:freebsd, p-cpe:/a:freebsd:freebsd:freebsd-kernel

Required KB Items: Host/local_checks_enabled, Settings/ParanoidReport, Host/FreeBSD/release, Host/FreeBSD/pkg_info

Exploit Ease: No known exploits are available

Patch Publication Date: 9/30/2026

Vulnerability Publication Date: 9/30/2026

Reference Information

CVE: CVE-2026-58099, CVE-2026-58100