CVE-2026-49415Freebsd · Freebsd
Vulnerability data via NVD (ingested)
During execve(2) of a SUID binary, the new virtual address space is installed before the process credentials are updated. During this window, a process running as the same user can access the target process's memory via procfs or linprocfs, because the kernel's debugging permission check still saw the original credentials. An unprivileged local user can exploit this race to modify the address space of a SUID binary before its credentials are elevated, potentially gaining full control of the affected system.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-49415os:"Freebsd"More intel sources (5)
vuln:CVE-2026-49415vulnerabilities.cve_id: CVE-2026-49415CVE-2026-49415CVE-2026-49415"CVE-2026-49415" exploit -site:nvd.nist.gov