DigiNews

Tech Watch by Johan Denoyer

← Back to articles

CVE-2026-45257: LPE in FreeBSD via kTLS-RX

Quality: 8/10 Relevance: 9/10

Summary

The article discusses CVE-2026-45257, a local privilege escalation in FreeBSD via kTLS-RX, detailing how unprivileged users can corrupt page-cache data and write attacker-controlled bytes into file pages. It outlines the three subsystem interactions enabling the LPE, the exploit demonstration against SUID binaries, affected versions, and mitigations including a sysctl workaround and the official patch. It is framed with satirical elements from BUMSRAKETE, but the technical content aligns with FreeBSD advisories.

🚀 Service construit par Johan Denoyer