Feed/CVE-2026-49428
CVE-2026-49428HIGHCVSS 8.4

CVE-2026-49428

Published Aug 19, 2026·Updated Aug 20, 2026

NVD Description

Certain system calls, such open(2) with the O_TRUNC flag set, and fspacectl(2), could incorrectly free memory in largepage objects. These operations are not permitted on largepage objects, but the implementation did not verify this. An unprivileged local user can abuse the bug to access freed kernel memory. This can be exploited to escalate privileges.

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free