CVE-2026-35547: Freebsd
High severity, CVSS 8.1. EPSS: 0.4% chance of exploitation in the next 30 days.
When processing the header of an incoming message, libnv failed to properly validate the message size. The lack of validation allows a malicious program to write outside the bounds of a heap allocation. This can trigger a crash or system panic, and it may be possible for an unprivileged user to exploit the bug to elevate their privileges.
Affected products
- Freebsd Freebsd: version 13.5 only; version 14.3 only; version 14.4 only; version 15.0 only
Published 2026-04-30. Last modified 2026-06-17.