CVE-2026-49414Disclosure(freebsd / freebsd)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch freebsd freebsd systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The ELF image activator cleared per-process ASLR preference flags for setuid binaries after the code that computes the PIE base address, rather than before. As a result, a user-requested ASLR disable was still in effect at the point where the base address was chosen. An unprivileged local user can disable ASLR for a setuid PIE binary by calling procctl(2) before execve(2). This makes exploitation of any separate memory corruption vulnerability in that binary significantly easier.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-179

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • freebsd

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 4 mentions (2026-06-27); latest day: 1
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
freebsd

3 versions affected across 1 product

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-06-27: 4Mentions · 2026-07-02: 1Patch / Workaround · 2026-07-02: 1Technical Details · 2026-06-27: 3Technical Details · 2026-07-02: 106-2707-02
Signal classification2 categories
Disclosure
480.0%
Patch
120.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-06-274
Disclosure4
2026-07-021
Patch1
Full discourse5 posts
  • Synacktiv@Synacktiv
    Patch

    A month ago we pointed our local LLM at #FreeBSD and it helped us find a local root exploit plus an ASLR bypass on SUID binaries to go with it 🚨 Both now patched (CVE-2026-49415 & CVE-2026-49414). Update your boxes! ➡️ https://www.freebsd.org/security/advisories/FreeBSD-SA-26:39.execve.asc ➡️ https://www.freebsd.org/security/advisories/FreeBSD-SA-26:32.elf.asc https://t.co/WgqLPCjiKV

    Post summary

    The author reports discovering local root exploits and an ASLR bypass for FreeBSD, but the primary focus is that CVE‑2026‑49415 and CVE‑2026‑49414 are now patched, urging users to update.

    21204084.7K
    21.5K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    A severe vulnerability was disclosed for FreeBSD (CVE-2026-49414) https://vuldb.com/vuln/374478

    Post summary

    The text reports that a severe vulnerability (CVE-2026-49414) for FreeBSD has been disclosed, but provides no further technical detail, proofs, or exploitation information.

    00010158
    2.2K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-49414 The ELF image activator cleared per-process ASLR preference flags for setuid binaries after the code that computes the PIE base address, rather than before. As a res… https://www.cve.org/CVERecord?id=CVE-2026-49414

    Post summary

    The excerpt references CVE‑2026‑49414, outlining how the ELF image activator mishandles ASLR preference flags for setuid binaries, constituting a disclosure without any mention of PoC, exploit, patches, or ongoing attacks.

    00010959
    57.7K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-49414 The ELF image activator cleared per-process ASLR preference flags for setuid binaries after the code that computes the PIE base address, rather than before. As a res… https://www.cve.org/CVERecord?id=CVE-2026-49414 ----- Traducción: CVE-2026-49414 El … http://infoflow.cloud`

    Post summary

    The tweet references CVE‑2026‑49414, detailing a bug where the ELF image activator mistakenly clears ASLR preference flags for setuid binaries. No PoC, exploit, patch, or active exploitation is discussed.

    0000029
    89 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-49414 Local Privilege Escalation via ASLR Bypass in ELF Setuid Binaries https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-49414

    Post summary

    The snippet announces CVE-2026-49414, outlining a local privilege escalation bug involving ASLR bypass in ELF setuid binaries, without providing PoC, exploit code, or mitigation details.

    00000152
    4.1K followersView on X
CPE platform detail31 entries

31 of 31 entries

PartVendorProductVersionTarget SWTarget HW
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.4--
OSfreebsdfreebsd14.4--
OSfreebsdfreebsd14.4--
OSfreebsdfreebsd14.4--
OSfreebsdfreebsd14.4--
OSfreebsdfreebsd14.4--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--

Explore more