CVE Explorer
CVE-2026-45250
The setcred(2) system call is only available to privileged users. However, before the privilege level of the caller is checked, the user-supplied list of supplementary groups is copied into a fixed-size kernel stack buffer without first validating its length. If the supplied list exceeds the capacity of that buffer, a stack buffer overflow occurs.
Because the bounds check on the supplementary groups list occurs after the kernel stack buffer has already been written, an unprivileged local user
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unknown","modules":["setcred"],"product":"FreeBSD","vendor":"FreeBSD","versions":[{"lessThan":"p9","status":"affected","version":"15.0-RELEASE","versionType":"release"},{"lessThan":"p5","status":"affected","version":"14.4-RELEASE","versionType":"release"},{"lessThan":"p14","status":"affected","version":"14.3-RELEASE","versionType":"release"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:139df69da06abc4e4e5b883fde2c89790f50827f43f5406e13aa61e43ad544bc · sha256:d96f9387ee257350… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:139df69da06abc4e4e5b883fde2c89790f50827f43f5406e13aa61e43ad544bc · sha256:d96f9387ee257350… · /containers/adp/0/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-121","description":"CWE-121: Stack-based Buffer Overflow","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:139df69da06abc4e4e5b883fde2c89790f50827f43f5406e13aa61e43ad544bc · sha256:d96f9387ee257350… · /containers/cna/problemTypes/0/descriptions/0
Source references
4 source assertions{"url":"http://www.openwall.com/lists/oss-security/2026/05/21/18"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:139df69da06abc4e4e5b883fde2c89790f50827f43f5406e13aa61e43ad544bc · sha256:d96f9387ee257350… · /containers/adp/1/references/1
{"url":"http://www.openwall.com/lists/oss-security/2026/05/21/3"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:139df69da06abc4e4e5b883fde2c89790f50827f43f5406e13aa61e43ad544bc · sha256:d96f9387ee257350… · /containers/adp/1/references/0
{"url":"http://www.openwall.com/lists/oss-security/2026/05/22/5"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:139df69da06abc4e4e5b883fde2c89790f50827f43f5406e13aa61e43ad544bc · sha256:d96f9387ee257350… · /containers/adp/1/references/2
{"tags":["vendor-advisory"],"url":"https://security.freebsd.org/advisories/FreeBSD-SA-26:18.setcred.asc"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:139df69da06abc4e4e5b883fde2c89790f50827f43f5406e13aa61e43ad544bc · sha256:d96f9387ee257350… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.