https://seclists.org/oss-sec/2026/q2/881: CVE-2026-45257: FeBSD kTLS-RX in-place AES-GCM decrypt over sendfile(2) EXTPG mbufs to page-cache write / local root
Published Jun 10, 2026
·Updated
Affected Software
1 affected component
FreeBSD FreeBSD>=13.0<=13.4, >=14.0<=14.2, =15.0-RELEASE
Frequently Asked Questions
1
What is the severity of CVE-2026-45257?
CVE-2026-45257 is a high-severity vulnerability that allows unprivileged users to write attacker-influenced bytes into the page-cache of any file they can read.
2
How do I fix CVE-2026-45257?
To mitigate CVE-2026-45257, update your FreeBSD system to a patched version that resolves the issue.
3
Who is affected by CVE-2026-45257?
CVE-2026-45257 affects unprivileged local users on FreeBSD systems version 13.0 and above with any PMAP_HAS_DMAP architecture.
4
What systems are impacted by CVE-2026-45257?
CVE-2026-45257 impacts FreeBSD systems running on amd64, arm64, and riscv architectures.
5
Can CVE-2026-45257 be exploited remotely?
CVE-2026-45257 cannot be exploited remotely as it requires local access to the affected FreeBSD system.