OpenBSD patches local root vulnerability

The OpenBSD project has published a patch (CVE-2026-57589) for a kernel vulnerability affecting the implementation of System V semaphores (sem) system calls. The issue is caused by a call to previously freed memory in the sys_semget() function and can be exploited to gain root privileges by an unprivileged local user in the default configuration.

The fix was included in the OpenBSD-current codebase on May 23rd, but patches for existing releases were only published today. The bug had been present in the code for 23 years and was discovered as part of the Patch the Planet initiative to validate open source projects with OpenAI AI models.

In addition to the noted problem, several fixes have been published that are not labeled as vulnerability fixes, but, judging by the description, may be security-related: insufficient input validation in IPsec and IPComp code; double memory free in server NFS; memory corruption in lock handling code in pinsyscall and kbind functions.

Source: opennet.ru

Buy reliable hosting for sites with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster