A local vulnerability allowing root access has been fixed in OpenBSD

The OpenBSD project has published a fix for a vulnerability (CVE-2026-57589) in the kernel that affects the implementation of System V semaphore (sem) system calls. The issue is due to accessing already freed memory in the sys_semget() function and can be exploited by an unprivileged local user to gain root privileges in a default configuration.

The fix was integrated into the OpenBSD-current codebase on May 23, but patches for already released versions have only been published today. The bug had been present in the code for 23 years and was discovered as part of the Patch the Planet initiative, which involves checking open-source projects using AI models from OpenAI.

In addition to the noted issue, several other fixes have been published that are not marked as vulnerability mitigations but may be related to security based on their descriptions: insufficient input validation in IPsec and IPComp code; double freeing of memory in server NFS; memory corruption in locking code in the pinsyscall and kbind functions.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster