Public Exploit Released for FreeBSD kTLS Local Root Flaw CVE-2026-45257
ID: c93f7a59-9247-57d9-94f9-0aaa355619ee
STIX ID: report--c93f7a59-9247-57d9-94f9-0aaa355619ee
Feed Name: securityonline.info
FreeBSD kTLS vulnerability CVE-2026-45257 allows unprivileged users to achieve local root by causing in-place AES-GCM decryption to overwrite file-backed page-cache pages (e.g., via sendfile on loopback), bypassing filesystem protections; a public technical write-up and working proof-of-concept were released on June 10, 2026, affecting FreeBSD 13.0–13.4, 14.0–14.2, and 15.0-RELEASE on direct-map architectures, and FreeBSD has released patches and recommended temporary sysctl mitigations (kern.ipc.mb_use_ext_pgs=0 or kern.ipc.tls.enable=0).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
