HarborGuard / CVE
Back to search
HIGHCVE-2026-35547Published Modified CNA freebsd

CVE-2026-35547: Heap overflow in libnv

When processing the header of an incoming message, libnv failed to properly validate the message size. The lack of validation allows a malicious program to write outside the bounds of a heap allocation. This can trigger a crash or system panic, and it may be possible for an unprivileged user to exploit the bug to elevate their privileges.

Metrics

CVSS v3.1
8.1
Severity
HIGH
Fixed in
p12
Affected Products
1

Fix available

p12p13p3p7
Affected packages
  • FreeBSD / FreeBSD
    < p7 (from 15.0-RELEASE) · < p3 (from 14.4-RELEASE) · < p12 (from 14.3-RELEASE) · < p13 (from 13.5-RELEASE)
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H