FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

FreeBSD -- Memory safety bugs in kqueue copy-on-fork implementation

Affected packages
15.1 <= FreeBSD-kernel < 15.1_4

Details

VuXML ID d725b228-bccc-11f1-906f-bc241121aa0a
Discovery 2026-09-29
Entry 2026-09-30

Problem Description:

When copying knotes from a parent kqueue to a child, the copy code did not correctly exclude marker knotes (used internally to track list traversal position) before marking them as in-flux and releasing the kqueue lock. If another thread freed a marker while the lock was dropped, the subsequent in-flux decrement operated on freed memory. (CVE-2026-58099)

kqueue_fork_copy_knote() indexed into the child's file descriptor table using a knote's file descriptor number without a bounds check. Because the child's table is copied before knotes are transferred, a concurrent thread in the parent could grow the parent's table and register knotes with file descriptor numbers beyond the end of the child's table, causing an out-of-bounds read. (CVE-2026-58100)

Impact:

An unprivileged local user may be able to exploit these races to escalate privileges.

References

CVE Name CVE-2026-58099
CVE Name CVE-2026-58100
FreeBSD Advisory SA-26:65.kqueue