← Back

CVE-2026-6386

nvd nist
Published: Apr 22, 2026Modified: Jun 17, 2026

JSON object

Loading...
6.2
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.5 / Impact: 3.6
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

In order to apply a particular protection key to an address range, the kernel must update the corresponding page table entries. The subroutine which handled this failed to take into account the presence of 1GB largepage mappings created using the shm_create_largepage(3) interface. In particular, it would always treat a page directory page entry as pointing to another page table page. The bug can be abused by an unprivileged user to cause pmap_pkru_update_range() to treat userspace memory as a page table page, and thus overwrite memory to which the application would otherwise not have access.

Affected (33)

Products: Freebsd: Freebsd
1 product
Freebsd
Configuration A
33 vulnerable
Vulnerable SoftwareAffected Versions
Freebsd
Version 13.5
Version 13.5 beta3
Version 13.5 p10
Version 13.5 p11
Version 13.5 p1
Version 13.5 p2
Version 13.5 p3
Version 13.5 p4
Version 13.5 p5
Version 13.5 p6
Version 13.5 p7
Version 13.5 p8
Version 13.5 p9
Version 14.3
Version 14.3 p10
Version 14.3 p1
Version 14.3 p2
Version 14.3 p3
Version 14.3 p4
Version 14.3 p5
Version 14.3 p6
Version 14.3 p7
Version 14.3 p8
Version 14.3 p9
Version 14.4
Version 14.4 p1
Version 14.4 rc1
Version 15.0
Version 15.0 p1
Version 15.0 p2
Version 15.0 p3
Version 15.0 p4
Version 15.0 p5

References (1)

Timeline

No history available yet.