https://seclists.org/oss-sec/2026/q2/882: CVE-2026-45257: FeBSD kTLS-RX in-place AES-GCM decrypt over sendfile(2) EXTPG mbufs to page-cache write / local root
Published Jun 10, 2026
·Updated
Affected Software
2 affected components
FreeBSD FreeBSD>=13.0<=13.4, >=14.0<=14.2, =15.0-RELEASE
MidnightBSD MidnightBSD>=4.0
Frequently Asked Questions
1
What is the severity of CVE-2026-45257?
CVE-2026-45257 is considered a high severity vulnerability due to its potential for local root privilege escalation.
2
How do I fix CVE-2026-45257?
To fix CVE-2026-45257, update FreeBSD or MidnightBSD to the latest patched version released after the vulnerability was identified.
3
What versions of FreeBSD are affected by CVE-2026-45257?
CVE-2026-45257 affects FreeBSD versions 13.0 through 13.4 and 14.0 through 14.2, as well as 15.0-RELEASE.
4
Can CVE-2026-45257 affect MidnightBSD?
Yes, CVE-2026-45257 can impact MidnightBSD versions 4.0 and above.
5
What type of attacks can exploit CVE-2026-45257?
CVE-2026-45257 can be exploited to perform local privilege escalation by manipulating AES-GCM decryption processes.