7.3
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Description
An operator precedence bug in the kernel results in a scenario where a buffer overflow causes attacker-controlled data to overwrite adjacent execve(2) argument buffers.
The bug may be exploitable by an unprivileged user to obtain superuser privileges.
The bug may be exploitable by an unprivileged user to obtain superuser privileges.
Basic Information
ID
CVE-2026-7270
Source
freebsd
Published
Apr 30, 2026 at 07:02
Modified
Apr 30, 2026 at 13:07
Affected Product
Vendor
FreeBSD
Product
FreeBSD
Version
15.0-RELEASE
Affected Versions
FreeBSD FreeBSD 15.0-RELEASE
FreeBSD FreeBSD 14.4-RELEASE
FreeBSD FreeBSD 14.3-RELEASE
FreeBSD FreeBSD 13.5-RELEASE
FreeBSD FreeBSD 14.4-RELEASE
FreeBSD FreeBSD 14.3-RELEASE
FreeBSD FreeBSD 13.5-RELEASE