Security Advisory

CVE-2026-49424

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-19 07:08:35
Last updated 2026-08-19 07:08:35
Assigner freebsd
CVSS score not scored
State PUBLISHED

Description

The Linux waitid() implementation translates a FreeBSD siginfo_t struct into a stack-declared Linux siginfo_t. It did not first zero the stack struct. An unprivileged user may observe 104 bytes of uninitialized kernel stack data, which may contain sensitive information.