CVE-2026-49416Disclosure(freebsd / freebsd)

LOWCVSS 7.8 · HIGH

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The CONS_HISTORY ioctl handler did not adequately validate the requested history size. A large value caused an integer overflow in the buffer size calculation, resulting in a heap allocation smaller than expected. Subsequent initialization of the buffer wrote beyond the end of the allocation. An unprivileged local user with access to a vt(4) device can trigger an out-of-bounds write in the kernel, potentially escalating privileges.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-190

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • freebsd

Threat summary

  • 4 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • 4 total mentions across 1 day

Affected systems

Vendors
Products
freebsd

3 versions affected across 1 product

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-06-27: 4Technical Details · 2026-06-27: 306-27
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets5 URLs
Full discourse4 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-49416 Integer Overflow in CONS_HISTORY ioctl Handler Causing Kernel Hea... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-49416 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The tweet announces CVE‑2026‑49416 as an integer overflow in the CONS_HISTORY ioctl handler, with no PoC, exploit code, active exploitation, or patch information provided.

    00010109
    4.1K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    A new vulnerability with increased severity was disclosed for FreeBSD (CVE-2026-49416) https://vuldb.com/vuln/374477

    Post summary

    The post announces the new disclosure of CVE-2026-49416 for FreeBSD, noting increased severity, but provides no further details on exploitation, patching, or technical specifics.

    00000160
    2.2K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-49416 The CONS_HISTORY ioctl handler did not adequately validate the requested history size. A large value caused an integer overflow in the buffer size calculation, resul… https://www.cve.org/CVERecord?id=CVE-2026-49416 ----- Traducción: CVE-2026-49416 El … http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-49416, describing an integer overflow in the CONS_HISTORY ioctl handler, but offers no PoC, exploit, active exploitation evidence, or patch information.

    0000034
    89 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-49416 The CONS_HISTORY ioctl handler did not adequately validate the requested history size. A large value caused an integer overflow in the buffer size calculation, resul… https://www.cve.org/CVERecord?id=CVE-2026-49416

    Post summary

    The snippet describes an integer overflow vulnerability in the CONS_HISTORY ioctl due to insufficient validation of the history size, but it does not mention exploitation, a PoC, patches, or active use.

    000001.0K
    57.7K followersView on X
CPE platform detail31 entries

31 of 31 entries

PartVendorProductVersionTarget SWTarget HW
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.4--
OSfreebsdfreebsd14.4--
OSfreebsdfreebsd14.4--
OSfreebsdfreebsd14.4--
OSfreebsdfreebsd14.4--
OSfreebsdfreebsd14.4--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--

Explore more