CVE-2026-49425: Freebsd
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
The compat32 kevent() handler translates a 64-bit kevent struct into a stack- declared 32-bit struct. It did not first zero the stack struct. An unprivileged user may observe a small amount of uninitialized kernel stack data, which may contain sensitive information.
Affected products
- Freebsd Freebsd: version 14.3 only; version 14.4 only; version 15.0 only
Published 2026-08-19. Last modified 2026-08-31.