FreeBSD : FreeBSD -- Heap out-of-bounds access in semop(2) (6ef25129-bccc-11f1-906f-bc241121aa0a)

high Nessus Plugin ID 353460

Language:

Synopsis

The remote FreeBSD host is missing one or more security-related updates.

Description

The version of FreeBSD installed on the remote host is prior to tested version. It is, therefore, affected by a vulnerability as referenced in the 6ef25129-bccc-11f1-906f-bc241121aa0a advisory.

When semop(2) blocks waiting for a semaphore condition, it releases the per-set lock and sleeps. Upon waking, it checks the sequence number embedded in the semaphore set's IPC identifier to detect whether the set was removed while the caller was asleep.
This sequence number is only 15 bits wide. If enough semaphore sets are created and destroyed in the same table slot while a caller is blocked, the counter wraps around, and semop(2) may falsely conclude that the original set still exists. The subsequent access to a semaphore within the set may then be out of bounds.
An unprivileged local user can trigger an out-of-bounds access on kernel heap memory, potentially leading to privilege escalation.

Tenable has extracted the preceding description block directly from the FreeBSD security advisory.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

http://www.nessus.org/u?86f5a413

Plugin Details

Severity: High

ID: 353460

File Name: freebsd_pkg_6ef25129bccc11f1906fbc241121aa0a.nasl

Version: 1.1

Type: Local

Published: 10/1/2026

Updated: 10/1/2026

Configuration: Enable paranoid mode

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.35

CVSS v2

Risk Factor: Medium

Base Score: 6.1

Temporal Score: 4.5

Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:C/A:P

CVSS Score Source: CVE-2026-58098

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:freebsd:freebsd, p-cpe:/a:freebsd:freebsd:freebsd-kernel

Required KB Items: Settings/ParanoidReport, Host/local_checks_enabled, Host/FreeBSD/release, Host/FreeBSD/pkg_info

Exploit Ease: No known exploits are available

Patch Publication Date: 9/30/2026

Vulnerability Publication Date: 9/30/2026

Reference Information

CVE: CVE-2026-58098