CVE-2026-6386Active Exploitation(freebsd / freebsd)

MEDIUMCVSS 6.2 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch freebsd freebsd systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

In order to apply a particular protection key to an address range, the kernel must update the corresponding page table entries. The subroutine which handled this failed to take into account the presence of 1GB largepage mappings created using the shm_create_largepage(3) interface. In particular, it would always treat a page directory page entry as pointing to another page table page. The bug can be abused by an unprivileged user to cause pmap_pkru_update_range() to treat userspace memory as a page table page, and thus overwrite memory to which the application would otherwise not have access.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269CWE-732

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • freebsd

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-22); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
freebsd

4 versions affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-22: 1Mentions · 2026-04-25: 1Active Exploitation · 2026-04-22: 1Patch / Workaround · 2026-04-22: 1Technical Details · 2026-04-22: 1Technical Details · 2026-04-25: 104-2204-25
Signal classification2 categories
Active Exploitation
150.0%
General
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-04-221
Active Exploitation1
2026-04-251
General1
Full discourse2 posts
  • CVE@CVEnew
    General

    CVE-2026-6386 In order to apply a particular protection key to an address range, the kernel must update the corresponding page table entries. The subroutine which handled this faile… https://www.cve.org/CVERecord?id=CVE-2026-6386

    Post summary

    The text provides a brief technical description of CVE‑2026‑6386, mentioning kernel page table update failure, but does not disclose a PoC, exploit, patch, or active exploitation activity.

    00000137
    57.3K followersView on X
  • NerdieNews@NewsNerdie
    Active Exploitation

    CVE-2026-6386 is under active exploitation—attackers can gain unauthorized access via the kernel's large page handling flaw. Patch now. This vulnerability could lead to severe data breaches. #NerdieNews #CyberSecurity #InfoSec #Vulnerability #SupplyChain #Microsoft #Linux https://t.co/bmB1MZXe19

    Post summary

    CVE-2026-6386 is reported to be actively exploited through a kernel large‑page handling flaw, prompting an urgent patch to prevent significant data breaches.

    0000032
    55 followersView on X
CPE platform detail33 entries

33 of 33 entries

PartVendorProductVersionTarget SWTarget HW
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.4--
OSfreebsdfreebsd14.4--
OSfreebsdfreebsd14.4--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--
OSfreebsdfreebsd15.0--

Explore more