HarborGuard / CVE
Back to search
HIGHCVE-2026-7270Published Modified CNA freebsd

CVE-2026-7270: Local privilege escalation via execve()

An operator precedence bug in the kernel results in a scenario where a buffer overflow causes attacker-controlled data to overwrite adjacent execve(2) argument buffers. The bug may be exploitable by an unprivileged user to obtain superuser privileges.

Metrics

CVSS v3.1
7.8
Severity
HIGH
Fixed in
p12
Affected Products
1

Fix available

p12p13p3p7
Affected packages
  • FreeBSD / FreeBSD
    < p7 (from 15.0-RELEASE) · < p3 (from 14.4-RELEASE) · < p12 (from 14.3-RELEASE) · < p13 (from 13.5-RELEASE)
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H