FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

FreeBSD -- Heap out-of-bounds access in semop(2)

Affected packages
15.1 <= FreeBSD-kernel < 15.1_4
15.0 <= FreeBSD-kernel < 15.0_14
14.5 <= FreeBSD-kernel < 14.5_1
14.4 <= FreeBSD-kernel < 14.4_10

Details

VuXML ID 6ef25129-bccc-11f1-906f-bc241121aa0a
Discovery 2026-09-29
Entry 2026-09-30

Problem Description:

When semop(2) blocks waiting for a semaphore condition, it releases the per-set lock and sleeps. Upon waking, it checks the sequence number embedded in the semaphore set's IPC identifier to detect whether the set was removed while the caller was asleep. This sequence number is only 15 bits wide. If enough semaphore sets are created and destroyed in the same table slot while a caller is blocked, the counter wraps around, and semop(2) may falsely conclude that the original set still exists. The subsequent access to a semaphore within the set may then be out of bounds.

Impact:

An unprivileged local user can trigger an out-of-bounds access on kernel heap memory, potentially leading to privilege escalation.

References

CVE Name CVE-2026-58098
FreeBSD Advisory SA-26:64.sysvsem