https://seclists.org/oss-sec/2026/q2/654: CVE-2026-45250: FeBSD setcd(2) stack overflow -> local privilege escalation (FatGid)
Published May 21, 2026
·Updated
Affected Software
1 affected component
FreeBSD FreeBSD>=14.0<15.0
Frequently Asked Questions
1
What is the severity of CVE-2026-45250?
CVE-2026-45250 has a high severity rating due to its nature as a stack buffer overflow that can lead to local privilege escalation.
2
How do I fix CVE-2026-45250?
To fix CVE-2026-45250, users should upgrade to the patched version of FreeBSD 14.x as provided in the security advisory.
3
Who is affected by CVE-2026-45250?
CVE-2026-45250 affects local users of FreeBSD 14.x who can exploit the stack buffer overflow due to insufficient privilege checks.
4
What systems are vulnerable to CVE-2026-45250?
CVE-2026-45250 is specifically a vulnerability in FreeBSD 14.x systems that have the setcred(2) system call implemented.
5
What kind of attack does CVE-2026-45250 allow?
CVE-2026-45250 allows a local unprivileged user to execute arbitrary code, potentially gaining elevated privileges on the system.