An unprivileged local user with access to a vt(4) device can trigger an out-of-bounds write in the kernel, potentially escalating privileges.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 29 Jun 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Sat, 27 Jun 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Freebsd
Freebsd freebsd |
|
| Vendors & Products |
Freebsd
Freebsd freebsd |
Sat, 27 Jun 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The CONS_HISTORY ioctl handler did not adequately validate the requested history size. A large value caused an integer overflow in the buffer size calculation, resulting in a heap allocation smaller than expected. Subsequent initialization of the buffer wrote beyond the end of the allocation. An unprivileged local user with access to a vt(4) device can trigger an out-of-bounds write in the kernel, potentially escalating privileges. | |
| Title | Integer overflow in vt(4) CONS_HISTORY ioctl | |
| Weaknesses | CWE-190 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: freebsd
Published:
Updated: 2026-06-30T03:55:30.184Z
Reserved: 2026-05-29T20:24:28.615Z
Link: CVE-2026-49416
Updated: 2026-06-29T19:43:30.911Z
Status : Analyzed
Published: 2026-06-27T10:16:38.077
Modified: 2026-07-01T14:04:11.063
Link: CVE-2026-49416
No data.
OpenCVE Enrichment
Updated: 2026-06-29T21:30:03Z