CVE-2026-45250Disclosure(freebsd / freebsd)

MEDIUMCVSS 7.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch freebsd freebsd systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

The setcred(2) system call is only available to privileged users. However, before the privilege level of the caller is checked, the user-supplied list of supplementary groups is copied into a fixed-size kernel stack buffer without first validating its length. If the supplied list exceeds the capacity of that buffer, a stack buffer overflow occurs. Because the bounds check on the supplementary groups list occurs after the kernel stack buffer has already been written, an unprivileged local user may trigger the overflow without holding any special privilege. Successful exploitation may allow an attacker to execute arbitrary code in the context of the kernel, allowing an unprivileged local user to gain elevated privileges on the affected system.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-121

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • freebsd

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 7 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • Peaked 4d ago at 2 mentions (2026-05-21); latest day: 1
  • 7 total mentions across 5 days

Affected systems

Vendors
Products
freebsd

3 versions affected across 1 product

Deep dive

Activity timeline7 mentions / 5d
01122Mentions · 2026-05-21: 2Mentions · 2026-05-22: 2Mentions · 2026-05-27: 1Mentions · 2026-05-29: 1Mentions · 2026-05-31: 1PoC Mentioned / Linked · 2026-05-27: 1PoC Mentioned / Linked · 2026-05-29: 1Exploit Tool / Code · 2026-05-27: 1Exploit Tool / Code · 2026-05-29: 1Patch / Workaround · 2026-05-27: 1Patch / Workaround · 2026-05-31: 1Technical Details · 2026-05-21: 2Technical Details · 2026-05-22: 2Technical Details · 2026-05-27: 1Technical Details · 2026-05-31: 105-2105-2205-2705-2905-31
Signal classification3 categories
Disclosure
457.1%
PoC
228.6%
Patch
114.3%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-05-212
Disclosure2
2026-05-222
Disclosure2
2026-05-271
PoC1
2026-05-291
PoC1
2026-05-311
Patch1
Full discourse7 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-45250,FatGid,FreeBSD-SA-26:18.setcred: FreeBSD: Stack buffer overflow via setcred(2) https://www.openwall.com/lists/oss-security/2026/05/21/3 introduced in FreeBSD 14.x. The overflow occurs before any privilege check, allowing local privilege escalation. https://x.com/venglin/status/2057321764128993778

    Post summary

    The text announces a stack buffer overflow in FreeBSD's setcred(2) that enables local privilege escalation, providing technical details but lacking PoC, exploit, or patch information.

    0501643.0K
    4.7K followersView on X
  • Gray Hats@the_yellow_fall
    PoC

    A critical FreeBSD setcred root exploit (CVE-2026-45250) bypasses SMAP/SMEP via stack corruption to grant local root access. Update your kernel immediately. #FreeBSD #CVE202645250 #FatGid #PrivilegeEscalation #KernelExploit #SysAdmin #Cybersecurity https://meterpreter.org/freebsd-setcred-root-exploit-cve-2026-45250/ https://t.co/5n719nCEcF

    Post summary

    A tweet announces a critical FreeBSD setcred root exploit (CVE-2026-45250) that bypasses SMAP/SMEP via stack corruption, shares a PoC link, and urges users to update their kernel immediately.

    00051588
    12.5K followersView on X
  • Mr. OS@ksg93rd
    PoC

    #exploit #Kernel_Security An AI audit of FreeBSD https://blog.calif.io/p/an-ai-audit-of-freebsd ]-> setcred (CVE-2026-45250) https://github.com/califio/publications/tree/main/MADBugs/freebsd/setcred-CVE-2026-45250 ]-> ptrace (CVE-2026-45253) https://github.com/califio/publications/tree/main/MADBugs/freebsd/ptrace-CVE-2026-45253 ]-> procdesc (CVE-2026-45251) https://github.com/califio/publications/tree/main/MADBugs/freebsd/file-CVE-2026-45251 ]-> Bonus https://github.com/califio/publications/tree/main/MADBugs/freebsd // Disclaimer

    Post summary

    The post highlights multiple FreeBSD CVEs and links to GitHub repositories containing proof‑of‑concept exploit code, but does not discuss active exploitation, patches, or technical details of the vulnerabilities.

    00003231
    3.3K followersView on X
  • AbcLinuxu.cz@abclinuxu
    Disclosure

    FatGid aneb CVE-2026-45250, lokální eskalace práv ve FreeBSD https://ift.tt/ZC8bnqx

    Post summary

    The tweet announces CVE‑2026‑45250, a local privilege‑escalation flaw in FreeBSD, providing a link for details but no PoC, exploit code, or patch information.

    01000126
    2.2K followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH: CVE-2026-45250 (CVSS 7.8) - Stack buffer overflow in setcred(2) system call allows unprivileged local users to gain elevated privileges via kernel code execution. Patch immediately. #CVE #Vulnerability #PatchNow #ThreatIntel https://t.co/Rvy7f1dPFm

    Post summary

    The post discloses a stack buffer overflow in setcred(2) that enables local privilege escalation and urges immediate patching.

    0000048
    33 followersView on X
  • DFIR Lab@DFIR_Lab
    Disclosure

    🚨 HIGH: CVE-2026-45250 (CVSS 7.8) setcred(2) stack buffer overflow allows unprivileged local users to gain root privileges via kernel code execution. Bounds check occurs AFTER buffer write. Affected: Systems with setcred(2) syscall #CVE #Vulnerability #PatchNow https://t.co/E2MhbOx6rd

    Post summary

    The tweet announces CVE-2026-45250, a kernel stack buffer overflow that enables local unprivileged users to gain root with a CVSS‑7.8 score; no exploit, patch, or active exploitation details are provided.

    0000059
    30 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-45250 The setcred(2) system call is only available to privileged users. However, before the privilege level of the caller is checked, the user-supplied list of supplementa… https://www.cve.org/CVERecord?id=CVE-2026-45250

    Post summary

    A disclosure highlights a privilege‑check bypass in the setcred(2) system call (CVE-2026-45250), providing technical details but no PoC, exploit, or patch information.

    00000137
    57.5K followersView on X
CPE platform detail29 entries

29 of 29 entries

PartVendorProductVersionTarget SWTarget HW
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.4--
OSfreebsdfreebsd14.4--
OSfreebsdfreebsd14.4--
OSfreebsdfreebsd14.4--
OSfreebsdfreebsd14.4--
OSfreebsdfreebsd14.4--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--

Explore more