CVE-2026-3038Disclosure(freebsd / freebsd)

MEDIUMCVSS 7.5 · HIGH

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Patch freebsd freebsd systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

The rtsock_msg_buffer() function serializes routing information into a buffer. As a part of this, it copies sockaddr structures into a sockaddr_storage structure on the stack. It assumes that the source sockaddr length field had already been validated, but this is not necessarily the case, and it's possible for a malicious userspace program to craft a request which triggers a 127-byte overflow. In practice, this overflow immediately overwrites the canary for the rtsock_msg_buffer() stack frame, resulting in a panic once the function returns. The bug allows an unprivileged user to crash the kernel by triggering a stack buffer overflow in rtsock_msg_buffer(). In particular, the overflow will corrupt a stack canary value that is verified when the function returns; this mitigates the impact of the stack overflow by triggering a kernel panic. Other kernel bugs may exist which allow userspace to find the canary value and thus defeat the mitigation, at which point local privilege escalation may be possible.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • freebsd

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 9 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 8 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 4 mentions (2026-03-09); latest day: 1
  • 9 total mentions across 6 days

Affected systems

Vendors
Products
freebsd

4 versions affected across 1 product

Deep dive

Activity timeline9 mentions / 6d
01234Mentions · 2026-02-25: 1Mentions · 2026-02-26: 1Mentions · 2026-03-09: 4Mentions · 2026-03-15: 1Mentions · 2026-06-17: 1Mentions · 2026-07-07: 1Active Exploitation · 2026-07-07: 1Patch / Workaround · 2026-02-26: 1Patch / Workaround · 2026-06-17: 1Technical Details · 2026-02-25: 1Technical Details · 2026-02-26: 1Technical Details · 2026-03-09: 3Technical Details · 2026-03-15: 1Technical Details · 2026-06-17: 1Technical Details · 2026-07-07: 102-2502-2603-0903-1506-1707-07
Signal classification4 categories
Disclosure
555.6%
Patch
222.2%
General
111.1%
Active Exploitation
111.1%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-02-251
Disclosure1
2026-02-261
Patch1
2026-03-094
Disclosure4
2026-03-151
General1
2026-06-171
Patch1
2026-07-071
Active Exploitation1
Full discourse9 posts
  • Praetorian@praetorianlabs
    Patch

    Adam Crosser pointed Claude Code at the FreeBSD kernel. Eight zero-days in days, including CVE-2026-3038 (RTSock stack overflow), patched a day after we reported it. Part one is the methodology: CodeQL triage, a KASAN feedback loop, and doing it on a $100 plan. 🔗 https://www.praetorian.com/blog/ai-vulnerability-research-freebsd-kernel/ #OffensiveSecurity #FreeBSD #Praetorian #InfoSec

    Post summary

    The post announces the discovery of seven zero‑day vulnerabilities in FreeBSD, reports CVE‑2026‑3038, and notes a patch was implemented the following day.

    0501261.0K
    8.7K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    FreeBSD patches a critical jail escape (CVE-2025-15576) and a kernel heap overflow (CVE-2026-3038). Learn how nullfs and routing sockets put hosts at risk. #FreeBSD #CyberSecurity #JailEscape #InfoSec #KernelSecurity #Vulnerability #SysAdmin #OpenSource https://securityonline.info/new-freebsd-vulnerabilities-allow-jail-escapes-and-kernel-panics/

    Post summary

    FreeBSD has released patches for CVE‑2025‑15576 (jail escape) and CVE‑2026‑3038 (kernel heap overflow), underscoring the risks posed by nullfs and routing sockets.

    00021319
    10.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-3038 Stack Buffer Overflow in FreeBSD Kernel rtsock_msg_buffer() Allows Local DoS https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3038

    Post summary

    The post discloses a stack buffer overflow in the FreeBSD kernel that can trigger a local denial‑of‑service, but provides no PoC, exploit code, patch, or evidence of active exploitation.

    0000146
    4.0K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    A new vulnerability with increased severity was disclosed for FreeBSD (CVE-2026-3038) https://vuldb.com/?id.349827

    Post summary

    A new vulnerability (CVE-2026-3038) affecting FreeBSD has been disclosed with increased severity but no PoC, exploit details, or technical specifics are shared.

    0000184
    2.1K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers exploiting CVE-2026-3038 can trigger kernel panics through crafted routing socket requests in FreeBSD systems. The stack buffer overflow demonstrates how input validation failures create immediate system availability risks. #Vulnerability 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/freebsd-kernel-vulnerability-cve-2026-3038

    Post summary

    The post reports that attackers are actively exploiting CVE-2026-3038 to cause kernel panics in FreeBSD via crafted routing socket requests, highlighting a stack buffer overflow issue.

    0000083
    1.9K followersView on X
  • slopjockey@sl0pjockey
    General

    Built a TLB timing KASLR bypass from Y2JB sandbox finds kernel base + security_flags page per boot, no native code needed. Also confirmed CVE-2026-3038 (PF_ROUTE sa_len heap overflow, 239 bytes controlled in malloc-256) is unpatched on 11.20. Full sandbox surface map, 70+ devices, 56 syscalls, GPU DMA from sandbox. All I need to complete the chain is Luac0re’s JIT for Spectre byte reads. I’m new to the community. Anyone able to help me get SWRR onto an 11.20 console that can’t reach PSN? @gezine_dev @calmboy2019 @Console_Hax

    Post summary

    The user reports technical details of an unpatched CVE and discusses preliminary steps toward building an exploit chain, but offers no PoC, exploit code, active exploitation claim, or patch information.

    000001
  • CVE@CVEnew
    Disclosure

    CVE-2026-3038 The rtsock_msg_buffer() function serializes routing information into a buffer. As a part of this, it copies sockaddr structures into a sockaddr_storage structure on th… https://www.cve.org/CVERecord?id=CVE-2026-3038

    Post summary

    The post briefly announces CVE‑2026‑3038, describing the vulnerable rtsock_msg_buffer() function and its data‑copy behavior, without providing a PoC, exploit code, or patch information.

    0000093
    56.6K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-3038 - Local DoS and possible privilege escalation via routing sockets Intel Report: https://ift.tt/nUtHNFV

    Post summary

    An alert announces CVE-2026-3038 as a local denial‑of‑service and potential privilege escalation via routing sockets, linking to an Intel report for details but offering no PoC, exploit, or patch information.

    0000030
    347 followersView on X
  • UNDERCODE TESTING@UndercodeUpdate
    Disclosure

    🚨 #FreeBSD Kernel Under Fire: New Critical Stack Overflow #CVE-2026-3038 Puts All Versions at Risk for Privilege Escalation + Video https://undercodetesting.com/freebsd-kernel-under-fire-new-critical-stack-overflow-cve-2026-3038-puts-all-versions-at-risk-for-privilege-escalation-video/ Educational Purposes!

    Post summary

    A new critical stack overflow vulnerability (CVE-2026-3038) in the FreeBSD kernel is disclosed, posing privilege escalation risk across all versions, with a video demonstration available.

    0000065
    400 followersView on X
CPE platform detail24 entries

24 of 24 entries

PartVendorProductVersionTarget SWTarget HW
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.4--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--

Explore more