In OpenBSD, a local vulnerability has been fixed that allowed obtaining root privileges.

The OpenBSD project has published a patch for the vulnerability (CVE-2026-57589) in the kernel, affecting the implementation of System V semaphore system calls (sem). The issue was caused by accessing already freed memory in the sys_semget() function and can be exploited by an unprivileged local user to gain root rights in a default configuration.

The fix was included in the OpenBSD-current codebase on May 23, but patches for already released versions were only published today. The error had been present in the code since 2023 and was identified during the Patch the Planet initiative, which verifies open-source projects using OpenAI models.

In addition to the noted issue, several fixes have been published that are not labeled as vulnerability mitigations but may be security-related based on the description: insufficient input validation in the IPsec and IPComp code; double memory freeing in server NFS; memory corruption in the code for handling locks in the pinsyscall and kbind functions.

Fonte: opennet.ru

Acquista un hosting affidabile per siti web con protezione DDoS, VPS VDS server 🔥 Acquista un hosting affidabile per siti web con protezione DDoS, VPS VDS server | ProHoster