Problem Description:
When copying knotes from a parent kqueue to a child, the copy
code did not correctly exclude marker knotes (used internally to
track list traversal position) before marking them as in-flux and
releasing the kqueue lock. If another thread freed a marker while
the lock was dropped, the subsequent in-flux decrement operated on
freed memory. (CVE-2026-58099)
kqueue_fork_copy_knote() indexed into the child's file descriptor
table using a knote's file descriptor number without a bounds check.
Because the child's table is copied before knotes are transferred,
a concurrent thread in the parent could grow the parent's table and
register knotes with file descriptor numbers beyond the end of the
child's table, causing an out-of-bounds read. (CVE-2026-58100)
Impact:
An unprivileged local user may be able to exploit these races
to escalate privileges.