FreeBSD libnv Heap Overflow Vulnerability Allowing Privilege Escalation

Vulnerability

A heap overflow vulnerability has been identified in the libnv library of FreeBSD. This issue arises because the library does not properly validate the size of incoming messages, allowing malicious programs to write outside the bounds of allocated memory. The vulnerability can lead to crashes or system panics, and may be exploitable by unprivileged users to elevate privileges.

Impact

Exploitation of this vulnerability can cause a heap overflow, leading to a crash or system panic. Additionally, it may allow an unprivileged user to escalate privileges.

Remediation

Users can upgrade to a supported FreeBSD stable or release branch dated after the correction date. Instructions for updating via the pkg utility, freebsd-update utility, or by applying a source code patch are available in the FreeBSD Security Advisory.

Added: Apr 30, 2026, 9:24 AM
Updated: Apr 30, 2026, 9:24 AM

Vulnerability Rating

Custom Algorithm
spread
5.4
impact
7.5
exploitability
2.7
remediation
7.7
relevance
7.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.