Description
The ZFS_IOC_RECV_NEW ioctl, in the heal receive path, similarly truncated a 64-bit payload size to a 32-bit integer for allocation, then used the original 64-bit size as the length for a byteswap operation.

A local user with the "receive" delegated ZFS permission can trigger kernel memory corruption via ZFS_IOC_RECV_NEW by sending a crafted receive stream in heal mode.
Published: 2026-08-19
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption (possible local privilege escalation)
Action: Apply patch
AI Analysis

Impact

The ZFS_IOC_RECV_NEW ioctl truncates a 64‑bit payload size to a 32‑bit integer when allocating a buffer, then later uses the original 64‑bit length for a bytes‑swap operation. This mismatch can corrupt kernel memory. A local user who has been delegated the ZFS "receive" permission can trigger this flaw by sending a crafted receive stream while the filesystem is in heal mode, potentially causing the kernel to crash or allowing the user to escape to root privileges.

Affected Systems

The vulnerability affects FreeBSD systems that include the ZFS filesystem. The advisory lists the FreeBSD kernel as the impacted product, but specific release or version information is not provided; the flaw exists in all current FreeBSD kernels that ship ZFS.

Risk and Exploitability

The flaw is classified as a local kernel heap overflow. Leveraging it requires the attacker to have local ZFS receive rights, so the attack vector is local. Exploitation would involve sending a malicious ZFS receive stream in heal mode so that the kernel can be corrupted and the attacker might attain higher privileges or cause a denial of service. The advisory lists a CVSS score of 7.8 and an EPSS score of <1%, and the vulnerability is not listed in CISA KEV. The high CVSS score indicates a significant risk, while the low EPSS score suggests limited exploitation probability at this time.

Generated by OpenCVE AI on August 26, 2026 at 20:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update FreeBSD to the latest release that contains the ZFS_IOC_RECV_NEW patch, ensuring the kernel is fully patched.
  • Restrict the ZFS "receive" permission to only trusted users or accounts that truly need it.
  • If the heal receive mode is not required in your environment, disable or block its use to eliminate the attack surface.

Generated by OpenCVE AI on August 26, 2026 at 20:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:freebsd:freebsd:14.3:-:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:14.3:p10:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:14.3:p11:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:14.3:p12:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:14.3:p13:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:14.3:p14:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:14.3:p15:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:14.3:p1:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:14.3:p2:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:14.3:p3:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:14.3:p4:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:14.3:p5:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:14.3:p6:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:14.3:p7:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:14.3:p8:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:14.3:p9:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:14.4:-:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:14.4:p1:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:14.4:p2:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:14.4:p3:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:14.4:p4:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:14.4:p5:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:14.4:p6:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:14.4:rc1:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:15.0:-:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:15.0:p10:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:15.0:p1:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:15.0:p2:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:15.0:p3:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:15.0:p4:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:15.0:p5:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:15.0:p6:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:15.0:p7:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:15.0:p8:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:15.0:p9:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:15.1:-:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:15.1:rc2:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:15.1:rc3-p1:*:*:*:*:*:*

Wed, 26 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Freebsd
Freebsd freebsd
Vendors & Products Freebsd
Freebsd freebsd

Wed, 19 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Description The ZFS_IOC_RECV_NEW ioctl, in the heal receive path, similarly truncated a 64-bit payload size to a 32-bit integer for allocation, then used the original 64-bit size as the length for a byteswap operation. A local user with the "receive" delegated ZFS permission can trigger kernel memory corruption via ZFS_IOC_RECV_NEW by sending a crafted receive stream in heal mode.
Title Kernel heap overflow in ZFS_IOC_RECV_NEW ioctl
Weaknesses CWE-122
References

cve-icon MITRE

Status: PUBLISHED

Assigner: freebsd

Published:

Updated: 2026-08-26T17:41:36.355Z

Reserved: 2026-05-29T20:24:28.616Z

Link: CVE-2026-49430

cve-icon Vulnrichment

Updated: 2026-08-26T17:41:30.954Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T06:17:42.767

Modified: 2026-09-01T20:05:45.343

Link: CVE-2026-49430

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T20:15:03Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow