CVE-2026-58090: Freebsd

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

The SOCK_STREAM receive path in the unix socket implementation failed to fully detach control messages from the socket buffer before processing them. Some error paths would free those messages, leaving freed data mbufs in the receive socket buffer. An unprivileged local user can exploit this use-after-free to escalate privileges.

Affected products

  • Freebsd Freebsd: version 15.0 only; version 15.1 only

Published 2026-08-26. Last modified 2026-09-24.