CVE-2026-35547Disclosure(freebsd / freebsd)

LOWCVSS 8.1 · HIGH

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

When processing the header of an incoming message, libnv failed to properly validate the message size. The lack of validation allows a malicious program to write outside the bounds of a heap allocation. This can trigger a crash or system panic, and it may be possible for an unprivileged user to exploit the bug to elevate their privileges.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122CWE-130

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • freebsd

Threat summary

  • 6 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 3 classified signals
  • Peaked at 4 mentions on most recent observed day (2026-05-12)
  • 6 total mentions across 2 days

Affected systems

Vendors
Products
freebsd

4 versions affected across 1 product

Deep dive

Activity timeline6 mentions / 2d
01234Mentions · 2026-04-30: 2Mentions · 2026-05-12: 4Technical Details · 2026-04-30: 1Technical Details · 2026-05-12: 304-3005-12
Signal classification2 categories
Disclosure
350.0%
General
350.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-302
Disclosure2
2026-05-124
Disclosure1General3
Full discourse6 posts
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE: CVE-2026-35547 CVSS: 9.1 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H Severity: CRITICAL Status: Critical advisory When processing the header of an incoming message, libnv failed to properly validate the message size.

    Post summary

    A critical CVE (CVE-2026-35547) is disclosed: libnv fails to validate incoming message size, posing a potential overflow risk. No PoC, exploit, or patch details are provided.

    1000044
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    CRITICAL: CVE-2026-35547 (CVSS 9.1) — multiple products. CVE: CVE-2026-35547 CVSS: 9.1 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The post announces CVE-2026-35547 as a critical vulnerability, providing its CVSS score and vector but offering no info on exploitation, patches, or PoC.

    1000042
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    --- Validated by the Lyrie Threat Intelligence Pipeline — 3 independent sources confirmed before publication. No speculation. CVE: CVE-2026-35547 CVSS: 9.1 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    A brief advisory documents CVE‑2026‑35547 with a critical CVSS score but lacks details on exploitation or remediation.

    1000038
    210 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    We have just added an important vulnerability affecting FreeBSD (CVE-2026-35547) https://vuldb.com/vuln/360290

    Post summary

    A new FreeBSD vulnerability (CVE-2026-35547) has been announced with a reference link, but no additional details, PoC, or mitigation information are provided.

    0000148
    2.1K followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-35547-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The provided text consists only of a URL and hashtags, with no substantive information about the CVE.

    0000021
    210 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-35547 Heap Buffer Overflow in libnv Message Header Processing Leading t... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-35547 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The statement discloses CVE-2026‑35547 as a heap buffer overflow in libnv message header processing, providing the vulnerability type but lacking any PoC, exploit, patch, or evidence of active exploitation.

    0000028
    4.0K followersView on X
CPE platform detail37 entries

37 of 37 entries

PartVendorProductVersionTarget SWTarget HW
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.4--
OSfreebsdfreebsd14.4--
OSfreebsdfreebsd14.4--
OSfreebsdfreebsd14.4--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--

Explore more