Beveiligingsadvies

CVE-2026-32848

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-05-18 17:52:55
Laatst bijgewerkt 2026-07-14 18:40:01
Toegewezen door VulnCheck
CVSS-score 5.7
Status PUBLISHED

Beschrijving

NetBSD prior to commit ec8451e contains a race condition vulnerability in cryptodev_op() within the opencrypto subsystem that allows local attackers to trigger a double-free condition by concurrently issuing CIOCCRYPT operations on the same session identifier on SMP systems. Attackers can exploit mutable per-operation state embedded in the csession struct to corrupt kernel heap memory.