Impact
A kernel operator precedence flaw causes a buffer overflow that lets an attacker overwrite adjacent execve(2) argument buffers, enabling exploitation of local privilege escalation to obtain superuser privileges.
Affected Systems
The advisory specifies the FreeBSD operating system as affected; vendor and product are FreeBSD:FreeBSD. No specific kernel or release version is disclosed in the advisory, so all current FreeBSD releases could be vulnerable until a patch is issued.
Risk and Exploitability
The CVSS score is 7.8, the EPSS score is <1%, and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of exploitation but high impact. Nevertheless, the local nature of the attack coupled with the high impact of gaining root privileges makes the risk substantial. An attacker with local access could trigger the buffer overflow and elevate privileges, then potentially compromise the entire system.
OpenCVE Enrichment