In order to apply a particular protection key to an address range, the kernel must update the corresponding page table entries. The subroutine which handled this failed to take into account the presence of 1GB largepage mappings created using the shm_create_largepage(3) interface. In particular, it would always treat a page directory page entry as pointing to another page table page. The bug can be abused by an unprivileged user to cause pmap_pkru_update_range() to treat userspace memory as a page table page, and thus overwrite memory to which the application would otherwise not have access.
This vulnerability carries a MEDIUM severity rating with a CVSS v3.1 score of 6.2, requiring local system access to exploit with relatively low complexity without requiring user interaction and does not require pre-existing privileges . The vulnerability impacts confidentiality (data exposure), for affected systems. Impacting 1 product from freebsd organizations running these solutions should prioritize assessment and patching.
Reported in 2026, this vulnerability emerged during an era marked by increased sophistication in supply chain attacks, cloud infrastructure vulnerabilities, and software-as-a-service (SaaS) security challenges. Security practices during this period emphasized zero-trust architectures, container security, and API protection.
2026-04-22T03:16:01.313
2026-05-01T12:49:08.827
Analyzed
CVSSv3.1: 6.2 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | freebsd | freebsd | 13.5 | Yes |
| Operating System | freebsd | freebsd | 13.5 | Yes |
| Operating System | freebsd | freebsd | 13.5 | Yes |
| Operating System | freebsd | freebsd | 13.5 | Yes |
| Operating System | freebsd | freebsd | 13.5 | Yes |
| Operating System | freebsd | freebsd | 13.5 | Yes |
| Operating System | freebsd | freebsd | 13.5 | Yes |
| Operating System | freebsd | freebsd | 13.5 | Yes |
| Operating System | freebsd | freebsd | 13.5 | Yes |
| Operating System | freebsd | freebsd | 13.5 | Yes |
| Operating System | freebsd | freebsd | 13.5 | Yes |
| Operating System | freebsd | freebsd | 13.5 | Yes |
| Operating System | freebsd | freebsd | 13.5 | Yes |
| Operating System | freebsd | freebsd | 14.3 | Yes |
| Operating System | freebsd | freebsd | 14.3 | Yes |
| Operating System | freebsd | freebsd | 14.3 | Yes |
| Operating System | freebsd | freebsd | 14.3 | Yes |
| Operating System | freebsd | freebsd | 14.3 | Yes |
| Operating System | freebsd | freebsd | 14.3 | Yes |
| Operating System | freebsd | freebsd | 14.3 | Yes |
| Operating System | freebsd | freebsd | 14.3 | Yes |
| Operating System | freebsd | freebsd | 14.3 | Yes |
| Operating System | freebsd | freebsd | 14.3 | Yes |
| Operating System | freebsd | freebsd | 14.3 | Yes |
| Operating System | freebsd | freebsd | 14.4 | Yes |
| Operating System | freebsd | freebsd | 14.4 | Yes |
| Operating System | freebsd | freebsd | 14.4 | Yes |
| Operating System | freebsd | freebsd | 15.0 | Yes |
| Operating System | freebsd | freebsd | 15.0 | Yes |
| Operating System | freebsd | freebsd | 15.0 | Yes |
| Operating System | freebsd | freebsd | 15.0 | Yes |
| Operating System | freebsd | freebsd | 15.0 | Yes |
| Operating System | freebsd | freebsd | 15.0 | Yes |
SecUtils normalizes and enriches National Vulnerability Database (NVD) records by standardizing vendor and product identifiers, aggregating vulnerability metadata from both NVD and MITRE sources, and providing structured context for security teams. For freebsd's affected products, we extract Common Platform Enumeration (CPE) data, Common Weakness Enumeration (CWE) classifications, CVSS severity metrics, and reference data to enable rapid vulnerability prioritization and asset correlation. This record contains no exploit code, proof-of-concept instructions, or attack methodologies—only defensive intelligence necessary for patch management, risk assessment, and security operations.