CVE Explorer
CVE-2026-49417
Second, the audio buffer backing a mapping could be freed when the device was closed even though the mapping remained valid. The freed memory could then be reused elsewhere while still accessible through the stale mapping.
The /dev/dsp device nodes are world-accessible by default. On a system with an audio device, either issue allows an unprivileged local user to read and write kernel memory, which can be used to escalate privileges, potentially gaining full control of the affected system. A
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unknown","modules":["sound"],"product":"FreeBSD","vendor":"FreeBSD","versions":[{"lessThan":"p10","status":"affected","version":"15.0-RELEASE","versionType":"release"},{"lessThan":"p6","status":"affected","version":"14.4-RELEASE","versionType":"release"},{"lessThan":"p15","status":"affected","version":"14.3-RELEASE","versionType":"release"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:9b707810919815ddea432d71d002659851467f525ce00bdba8ab6a4af408675f · sha256:ea7d9d0978c432d1… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":7,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:9b707810919815ddea432d71d002659851467f525ce00bdba8ab6a4af408675f · sha256:ea7d9d0978c432d1… · /containers/adp/0/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-416","description":"CWE-416: Use After Free","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:9b707810919815ddea432d71d002659851467f525ce00bdba8ab6a4af408675f · sha256:ea7d9d0978c432d1… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"tags":["vendor-advisory"],"url":"https://security.freebsd.org/advisories/FreeBSD-SA-26:27.sound.asc"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:9b707810919815ddea432d71d002659851467f525ce00bdba8ab6a4af408675f · sha256:ea7d9d0978c432d1… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.