-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
=============================================================================
FreeBSD-SA-26:65.kqueue Security Advisory
The FreeBSD Project
Topic: Memory safety bugs in kqueue copy-on-fork implementation
Category: core
Module: kqueue
Announced: 2026-09-29
Credits: Reo Shiseki
Credits: Mark Johnston
Affects: FreeBSD 15.1
Corrected: 2026-09-29 15:56:19 UTC (stable/15, 15.1-STABLE)
2026-09-29 16:00:04 UTC (releng/15.1, 15.1-RELEASE-p4)
CVE Name: CVE-2026-58099, CVE-2026-58100
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit .
I. Background
The kqueue(2) system call provides a scalable mechanism for kernel event
notification. Processes register interest in events using knotes, and
kqueue notifies them when registered events occur. kqueue also supports a
copy-on-fork mode (KQUEUE_CPONFORK) in which knotes are duplicated into the
child process during fork(2).
II. Problem Description
When copying knotes from a parent kqueue to a child, the copy code did
not correctly exclude marker knotes (used internally to track list
traversal position) before marking them as in-flux and releasing the
kqueue lock. If another thread freed a marker while the lock was
dropped, the subsequent in-flux decrement operated on freed memory.
(CVE-2026-58099)
kqueue_fork_copy_knote() indexed into the child's file descriptor
table using a knote's file descriptor number without a bounds check.
Because the child's table is copied before knotes are transferred, a
concurrent thread in the parent could grow the parent's table and
register knotes with file descriptor numbers beyond the end of the
child's table, causing an out-of-bounds read. (CVE-2026-58100)
III. Impact
An unprivileged local user may be able to exploit these races to escalate
privileges.
IV. Workaround
No workaround is available.
V. Solution
Upgrade your vulnerable system to a supported FreeBSD stable or
release / security branch (releng) dated after the correction date,
and reboot the system.
Perform one of the following:
1) To update your vulnerable system installed from base system packages:
Systems running a 15.0-RELEASE or later version of FreeBSD on the amd64 or
arm64 platforms, which were installed using base system packages, can be
updated via the pkg(8) utility:
# pkg upgrade -r FreeBSD-base
# shutdown -r +10min "Rebooting for a security update"
2) To update your vulnerable system installed from binary distribution sets:
Systems running a RELEASE version of FreeBSD on the amd64 or arm64 platforms
which were not installed using base system packages can be updated via the
freebsd-update(8) utility:
# freebsd-update fetch
# freebsd-update install
# shutdown -r +10min "Rebooting for a security update"
3) To update your vulnerable system via a source code patch:
The following patches have been verified to apply to the applicable
FreeBSD release branches.
a) Download the relevant patch from the location below, and verify the
detached PGP signature using your PGP utility.
# fetch https://security.FreeBSD.org/patches/SA-26:65/kqueue.patch
# fetch https://security.FreeBSD.org/patches/SA-26:65/kqueue.patch.asc
# gpg --verify kqueue.patch.asc
b) Apply the patch. Execute the following commands as root:
# cd /usr/src
# patch -E -p0 < /path/to/patch
c) Recompile your kernel as described in
and reboot the
system.
VI. Correction details
This issue is corrected as of the corresponding Git commit hash in the
following stable and release branches:
Branch/path Hash Revision
- -------------------------------------------------------------------------
stable/15/ 5db05b5dedf3 stable/15-n285678
releng/15.1/ 2b66c28a0383 releng/15.1-n283617
- -------------------------------------------------------------------------
Run the following command to see which files were modified by a
particular commit:
# git show --stat
Or visit the following URL, replacing NNNNNN with the hash:
To determine the commit count in a working tree (for comparison against
nNNNNNN in the table above), run:
# git rev-list --count --first-parent HEAD
VII. References
The latest revision of this advisory is available at
-----BEGIN PGP SIGNATURE-----
iQJPBAEBCgA5FiEEthUnfoEIffdcgYM7bljekB8AGu8FAmq8DLQbFIAAAAAABAAO
bWFudTIsMi41KzEuMTIsMCwzAAoJEG5Y3pAfABrvR40P/303lDROS4wJawGiimer
lZAMchuNXv9/caxxigTVNIgQ65tR9rIu5BkQxZ2ilSTOpJ0MvItXBP3W2P2583Tv
t8lPDqxHeXCpz3ESq/U/16Qaq11/gFOHLIezVZhNi3TbdUAOi2zKCIO7KUyGjYfm
j5Qdky5spzp3Ik03BEvaANOl2qvjWEKTz/syEc++vJXV1nvttSZRUbZDM6jkfOXZ
DckIsoa2ZIhIC1+bXMl4GztVepHlnuXcTg/VVxoNRmw5as8rVWycT17oyBSG+ATt
GUWW5s7tKd75iqxR4HdWACI4tidohDlGHWL7ej0WlAiYEV1WyhX8smwYNzM+bCYL
5ylQXw25bW8Jnrl88Uhpgp9qIII1rfLJKVwkXlrxifH9t24PrYGVM8hwsuY9umt7
ff+edIuSV3xelPgiMbfFd9o5cWKLMfkrFGLq0ELpH4IHU85B9OydUitTF1MoE4Zq
7ZUxrujaZFV9UuB1Znqfn7nf+UlmQVPT/QyQXbjNid0qgKjdZuEEaF4al7kvj+Cs
AE/ZsCpYb30MUcNA8A/pP+K0BPMAKQm0ls6lCW15k5gjROy3GcnvUo+ekSYmQab7
V1ToPsBwFt98ARJBeMFCrZUYAUuQA6s6o/dUduLNoGepmr8yXxAUopQr6K9SW7pT
dyQUI5qCsNFh2qwxlI3JIyR+
=wM7V
-----END PGP SIGNATURE-----