CVE Explorer
CVE-2026-4747
Each RPCSEC_GSS data packet is validated by a routine which checks a signature in the packet. This routine copies a portion of the packet into a stack buffer, but fails to ensure that the buffer is sufficiently large, and a malicious client can trigger a stack overflow. Notably, this does not require the client to authenticate itself first.
As kgssapi.ko's RPCSEC_GSS implementation is vulnerable, remote code execution in the kernel is possible by an authenticated user that is able to send pac
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unknown","modules":["rpcsec_gss"],"product":"FreeBSD","vendor":"FreeBSD","versions":[{"lessThan":"p5","status":"affected","version":"15.0-RELEASE","versionType":"release"},{"lessThan":"p1","status":"affected","version":"14.4-RELEASE","versionType":"release"},{"lessThan":"p10","status":"affected","version":"14.3-RELEASE","versionType":"release"},{"lessThan":"p11","status":"affected","version":"13.5-RELEASE","versionType":"release"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:aead1f75d893527e8996413cbd782636263ec459fa18f9aeb7fe60f400c867a1 · sha256:babae9cc67d33021… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:aead1f75d893527e8996413cbd782636263ec459fa18f9aeb7fe60f400c867a1 · sha256:babae9cc67d33021… · /containers/adp/0/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-121","description":"CWE-121: Stack-based Buffer Overflow","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:aead1f75d893527e8996413cbd782636263ec459fa18f9aeb7fe60f400c867a1 · sha256:babae9cc67d33021… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"tags":["exploit"],"url":"https://github.com/califio/publications/blob/main/MADBugs/CVE-2026-4747/exploit.py"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:aead1f75d893527e8996413cbd782636263ec459fa18f9aeb7fe60f400c867a1 · sha256:babae9cc67d33021… · /containers/adp/0/references/0
{"url":"https://github.com/califio/publications/tree/main/MADBugs/CVE-2026-4747"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:aead1f75d893527e8996413cbd782636263ec459fa18f9aeb7fe60f400c867a1 · sha256:babae9cc67d33021… · /containers/adp/1/references/0
{"tags":["vendor-advisory"],"url":"https://security.freebsd.org/advisories/FreeBSD-SA-26:08.rpcsec_gss.asc"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:aead1f75d893527e8996413cbd782636263ec459fa18f9aeb7fe60f400c867a1 · sha256:babae9cc67d33021… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.