Back to CVE List

CVE-2026-35547

Vulnerability Description

When processing the header of an incoming message, libnv failed to properly validate the message size.

The lack of validation allows a malicious program to write outside the bounds of a heap allocation. This can trigger a crash or system panic, and it may be possible for an unprivileged user to exploit the bug to elevate their privileges.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-122
Source
NVD
Vendor
FreeBSD
Product
FreeBSD

External References

Discussion (0)

Add Comment

No comments yet. Be the first!