CVE-2026-57589: OpenBSD
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
sys/kern/sysv_sem.c in OpenBSD through 7.9 has a use-after-free allowing local privilege escalation to root. This is a context switch use-after-free after tsleep in sys_semget().
Affected products
- OpenBSD OpenBSD: up to and including 7.9
Published 2026-06-25. Last modified 2026-07-10.