CVE-2026-58085Disclosure(freebsd / freebsd)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

After dispatching a decrypt operation to OCF and receiving the result, the wg(4) driver failed to check whether the MAC verification step succeeded. The driver thus silently accepted packets with an invalid Poly1305 authentication tag. A remote attacker who can send UDP packets to a WireGuard endpoint, and who can guess the bounds of the receiver's replay window, can inject forged or modified transport data packets into the tunnel. A remote attacker who can intercept WireGuard packets bound for a FreeBSD host can modify the ciphertext and authenticated data without detection by the receiver.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-347

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • freebsd

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-08-19); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
freebsd

3 versions affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-08-19: 1Mentions · 2026-08-20: 1Technical Details · 2026-08-19: 108-1908-20
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-08-191
Disclosure1
2026-08-201
General1
Full discourse2 posts
  • ばにらびいんず(鳥)@n01e0
    General

    渋いCVE https://www.cve.org/CVERecord?id=CVE-2026-58085

    Post summary

    The tweet simply acknowledges CVE-2026-58085 by linking to its CVE record, without any additional context or actionable information.

    1002502.8K
    1.7K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-58085 After dispatching a decrypt operation to OCF and receiving the result, the wg(4) driver failed to check whether the MAC verification step succeeded. The driver thus … https://www.cve.org/CVERecord?id=CVE-2026-58085

    Post summary

    The statement discloses a missing MAC check in the wg(4) driver following decryption, offering concise technical detail but lacking PoC, exploit, or mitigation information.

    00000709
    58.0K followersView on X
CPE platform detail25 entries

25 of 25 entries

PartVendorProductVersionTarget SWTarget HW
OSfreebsdfreebsd14.4--
OSfreebsdfreebsd14.4--
OSfreebsdfreebsd14.4--
OSfreebsdfreebsd14.4--
OSfreebsdfreebsd14.4--
OSfreebsdfreebsd14.4--
OSfreebsdfreebsd14.4--
OSfreebsdfreebsd14.4--
OSfreebsdfreebsd14.4--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.1--
OSfreebsdfreebsd15.1--
OSfreebsdfreebsd15.1--
OSfreebsdfreebsd15.1--

Explore more