-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 ============================================================================= FreeBSD-SA-26:65.kqueue Security Advisory The FreeBSD Project Topic: Memory safety bugs in kqueue copy-on-fork implementation Category: core Module: kqueue Announced: 2026-09-29 Credits: Reo Shiseki Credits: Mark Johnston Affects: FreeBSD 15.1 Corrected: 2026-09-29 15:56:19 UTC (stable/15, 15.1-STABLE) 2026-09-29 16:00:04 UTC (releng/15.1, 15.1-RELEASE-p4) CVE Name: CVE-2026-58099, CVE-2026-58100 For general information regarding FreeBSD Security Advisories, including descriptions of the fields above, security branches, and the following sections, please visit . I. Background The kqueue(2) system call provides a scalable mechanism for kernel event notification. Processes register interest in events using knotes, and kqueue notifies them when registered events occur. kqueue also supports a copy-on-fork mode (KQUEUE_CPONFORK) in which knotes are duplicated into the child process during fork(2). II. Problem Description When copying knotes from a parent kqueue to a child, the copy code did not correctly exclude marker knotes (used internally to track list traversal position) before marking them as in-flux and releasing the kqueue lock. If another thread freed a marker while the lock was dropped, the subsequent in-flux decrement operated on freed memory. (CVE-2026-58099) kqueue_fork_copy_knote() indexed into the child's file descriptor table using a knote's file descriptor number without a bounds check. Because the child's table is copied before knotes are transferred, a concurrent thread in the parent could grow the parent's table and register knotes with file descriptor numbers beyond the end of the child's table, causing an out-of-bounds read. (CVE-2026-58100) III. Impact An unprivileged local user may be able to exploit these races to escalate privileges. IV. Workaround No workaround is available. V. Solution Upgrade your vulnerable system to a supported FreeBSD stable or release / security branch (releng) dated after the correction date, and reboot the system. Perform one of the following: 1) To update your vulnerable system installed from base system packages: Systems running a 15.0-RELEASE or later version of FreeBSD on the amd64 or arm64 platforms, which were installed using base system packages, can be updated via the pkg(8) utility: # pkg upgrade -r FreeBSD-base # shutdown -r +10min "Rebooting for a security update" 2) To update your vulnerable system installed from binary distribution sets: Systems running a RELEASE version of FreeBSD on the amd64 or arm64 platforms which were not installed using base system packages can be updated via the freebsd-update(8) utility: # freebsd-update fetch # freebsd-update install # shutdown -r +10min "Rebooting for a security update" 3) To update your vulnerable system via a source code patch: The following patches have been verified to apply to the applicable FreeBSD release branches. a) Download the relevant patch from the location below, and verify the detached PGP signature using your PGP utility. # fetch https://security.FreeBSD.org/patches/SA-26:65/kqueue.patch # fetch https://security.FreeBSD.org/patches/SA-26:65/kqueue.patch.asc # gpg --verify kqueue.patch.asc b) Apply the patch. Execute the following commands as root: # cd /usr/src # patch -E -p0 < /path/to/patch c) Recompile your kernel as described in and reboot the system. VI. Correction details This issue is corrected as of the corresponding Git commit hash in the following stable and release branches: Branch/path Hash Revision - ------------------------------------------------------------------------- stable/15/ 5db05b5dedf3 stable/15-n285678 releng/15.1/ 2b66c28a0383 releng/15.1-n283617 - ------------------------------------------------------------------------- Run the following command to see which files were modified by a particular commit: # git show --stat Or visit the following URL, replacing NNNNNN with the hash: To determine the commit count in a working tree (for comparison against nNNNNNN in the table above), run: # git rev-list --count --first-parent HEAD VII. References The latest revision of this advisory is available at -----BEGIN PGP SIGNATURE----- iQJPBAEBCgA5FiEEthUnfoEIffdcgYM7bljekB8AGu8FAmq8DLQbFIAAAAAABAAO bWFudTIsMi41KzEuMTIsMCwzAAoJEG5Y3pAfABrvR40P/303lDROS4wJawGiimer lZAMchuNXv9/caxxigTVNIgQ65tR9rIu5BkQxZ2ilSTOpJ0MvItXBP3W2P2583Tv t8lPDqxHeXCpz3ESq/U/16Qaq11/gFOHLIezVZhNi3TbdUAOi2zKCIO7KUyGjYfm j5Qdky5spzp3Ik03BEvaANOl2qvjWEKTz/syEc++vJXV1nvttSZRUbZDM6jkfOXZ DckIsoa2ZIhIC1+bXMl4GztVepHlnuXcTg/VVxoNRmw5as8rVWycT17oyBSG+ATt GUWW5s7tKd75iqxR4HdWACI4tidohDlGHWL7ej0WlAiYEV1WyhX8smwYNzM+bCYL 5ylQXw25bW8Jnrl88Uhpgp9qIII1rfLJKVwkXlrxifH9t24PrYGVM8hwsuY9umt7 ff+edIuSV3xelPgiMbfFd9o5cWKLMfkrFGLq0ELpH4IHU85B9OydUitTF1MoE4Zq 7ZUxrujaZFV9UuB1Znqfn7nf+UlmQVPT/QyQXbjNid0qgKjdZuEEaF4al7kvj+Cs AE/ZsCpYb30MUcNA8A/pP+K0BPMAKQm0ls6lCW15k5gjROy3GcnvUo+ekSYmQab7 V1ToPsBwFt98ARJBeMFCrZUYAUuQA6s6o/dUduLNoGepmr8yXxAUopQr6K9SW7pT dyQUI5qCsNFh2qwxlI3JIyR+ =wM7V -----END PGP SIGNATURE-----