Security Advisory

CVE-2026-32848

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-05-18 17:52:55
Last updated 2026-07-14 18:40:01
Assigner VulnCheck
CVSS score 5.7
State PUBLISHED

Description

NetBSD prior to commit ec8451e contains a race condition vulnerability in cryptodev_op() within the opencrypto subsystem that allows local attackers to trigger a double-free condition by concurrently issuing CIOCCRYPT operations on the same session identifier on SMP systems. Attackers can exploit mutable per-operation state embedded in the csession struct to corrupt kernel heap memory.