CVE-2026-39461Patch(freebsd / freebsd)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch freebsd freebsd systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

libcasper(3) communicates with helper processes via UNIX domain sockets, and uses the select(2) system call to wait for data to become available. However, it does not verify that its socket descriptor fits within select(2)'s descriptor set size limit of FD_SETSIZE (1024). An attacker able to cause an application using libcasper(3) to allocate large file descriptors, e.g., by opening many descriptors and executing a program which is not careful to close them upon startup, may trigger stack corruption. If the target application runs with setuid root privileges, this could be used to escalate local privileges.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-121

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • freebsd

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 2 signals
  • Peaked 1d ago at 2 mentions (2026-05-22); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
freebsd

3 versions affected across 1 product

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-22: 2Mentions · 2026-05-31: 1Patch / Workaround · 2026-05-22: 2Patch / Workaround · 2026-05-31: 1Technical Details · 2026-05-22: 1Technical Details · 2026-05-31: 105-2205-31
Signal classification1 categories
Patch
3100.0%
Classification over time
DateTotalLabels
2026-05-222
Patch2
2026-05-311
Patch1
Full discourse3 posts
  • MidnightBSD@midnightbsd
    Patch

    The FreeBSD project released a number of security advisories yesterday. We're still reviewing them. So far, one does not impact MidnightBSD (setcred), and two more do: CVE-2026-39461 (libcasper) and CVE-2026-45254. We've patched the latter in git on master and stable/4.0

    Post summary

    FreeBSD posts advisories, confirms patching of CVE-2026-45254 in git master and stable/4.0 branches.

    02060199
    1.9K followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH severity CVE-2026-39461 (CVSS 8.8) affects libcasper(3) in FreeBSD. Stack corruption flaw allows local privilege escalation to root via file descriptor manipulation. Patch immediately if running setuid root apps. #CVE #Vulnerability #PatchNow #ThreatIntel https://t.co/TBKpV3svZN

    Post summary

    The tweet announces CVE‑2026‑39461, a stack‑corruption flaw in libcasper(3) on FreeBSD that permits local privilege escalation to root via file descriptor manipulation. It urges patching immediately for systems running setuid root applications.

    0000043
    33 followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH Severity: CVE-2026-39461 (CVSS 8.8) FreeBSD libcasper(3) stack corruption flaw enables local privilege escalation to root. Affects setuid applications using libcasper via FD_SETSIZE overflow. Patch immediately. #CVE #Vulnerability #PatchNow https://t.co/pQ0ntNcHDm

    Post summary

    The tweet announces a high-severity stack corruption vulnerability (CVE-2026-39461) in FreeBSD libcasper that allows local privilege escalation, urging users to apply a patch immediately.

    0000068
    30 followersView on X
CPE platform detail29 entries

29 of 29 entries

PartVendorProductVersionTarget SWTarget HW
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.4--
OSfreebsdfreebsd14.4--
OSfreebsdfreebsd14.4--
OSfreebsdfreebsd14.4--
OSfreebsdfreebsd14.4--
OSfreebsdfreebsd14.4--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--

Explore more