CVE Explorer
CVE-2026-39461
libcasper(3) communicates with helper processes via UNIX domain sockets, and uses the select(2) system call to wait for data to become available. However, it does not verify that its socket descriptor fits within select(2)'s descriptor set size limit of FD_SETSIZE (1024).
An attacker able to cause an application using libcasper(3) to allocate large file descriptors, e.g., by opening many descriptors and executing a program which is not careful to close them upon startup, may trigger stack corr
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unknown","modules":["libcasper"],"product":"FreeBSD","vendor":"FreeBSD","versions":[{"lessThan":"p9","status":"affected","version":"15.0-RELEASE","versionType":"release"},{"lessThan":"p5","status":"affected","version":"14.4-RELEASE","versionType":"release"},{"lessThan":"p14","status":"affected","version":"14.3-RELEASE","versionType":"release"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:fbd96c980cce65472f2e94170284f412e4559c98a0c0191c4a052090983ba240 · sha256:18a103e6d0c84bdd… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:fbd96c980cce65472f2e94170284f412e4559c98a0c0191c4a052090983ba240 · sha256:18a103e6d0c84bdd… · /containers/adp/0/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-121","description":"CWE-121: Stack-based Buffer Overflow","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:fbd96c980cce65472f2e94170284f412e4559c98a0c0191c4a052090983ba240 · sha256:18a103e6d0c84bdd… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"tags":["vendor-advisory"],"url":"https://security.freebsd.org/advisories/FreeBSD-SA-26:22.libcasper.asc"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:fbd96c980cce65472f2e94170284f412e4559c98a0c0191c4a052090983ba240 · sha256:18a103e6d0c84bdd… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.