High severity7.8NVD Advisory· Published Aug 26, 2026· Updated Sep 24, 2026
CVE-2026-58094
CVE-2026-58094
Description
The FIOSSHMLPGCNF ioctl(2) operation configures the page size for a largepage shared memory object. This is intended to be used immediately after creating the object, before any memory is allocated for the object. The handler checked whether a page size had already been configured without holding the rangelock. Two concurrent callers could both observe an unconfigured object and set conflicting page sizes, leaving the object in an inconsistent state.
An unprivileged local user can exploit this race to escalate privileges.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
1- security.freebsd.org/advisories/FreeBSD-SA-26:63.posixshm.ascnvdVendor Advisory
News mentions
0No linked articles in our index yet.