CVE-2026-32849Disclosure

LOWCVSS 5.7 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

NetBSD prior to commit ec8451e contains a signed integer overflow vulnerability in the cryptodev_op() function in sys/opencrypto/cryptodev.c where the local variable iov_len is declared as a signed int but assigned from an unsigned cop->dst_len value, causing undefined behavior when cop->dst_len exceeds INT_MAX. A local attacker with access to /dev/crypto and a compression session type can exploit this vulnerability by providing a dst_len value exceeding INT_MAX to trigger a kernel panic through NULL pointer dereference when CONFIG_SVS is disabled and corrupted UIO pointer arithmetic.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-190CWE-476

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-05-18: 1Technical Details · 2026-05-18: 105-18
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-32849 Signed Integer Overflow in NetBSD Cryptodev_op Function Kernel Panic https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-32849

    Post summary

    The text reports a new CVE involving a signed integer overflow in NetBSD’s cryptodev_op function that can trigger a kernel panic, but it does not provide PoC code, exploit tools, evidence of active exploitation, or patch information.

    0000186
    4.0K followersView on X

Explore more