CVE-2026-57589: OpenBSD

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

sys/kern/sysv_sem.c in OpenBSD through 7.9 has a use-after-free allowing local privilege escalation to root. This is a context switch use-after-free after tsleep in sys_semget().

Affected products

  • OpenBSD OpenBSD: up to and including 7.9

Published 2026-06-25. Last modified 2026-07-10.