The CONS_HISTORY ioctl handler did not adequately validate the requested history size. A large value caused an integer overflow in the buffer size calculation, resulting in a heap allocation smaller than expected. Subsequent initialization of the buffer wrote beyond the end of the allocation.
An unprivileged local user with access to a vt(4) device can trigger an out-of-bounds write in the kernel, potentially escalating privileges.
Metrics
Affected Vendors & Products
References
History
Sat, 27 Jun 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The CONS_HISTORY ioctl handler did not adequately validate the requested history size. A large value caused an integer overflow in the buffer size calculation, resulting in a heap allocation smaller than expected. Subsequent initialization of the buffer wrote beyond the end of the allocation. An unprivileged local user with access to a vt(4) device can trigger an out-of-bounds write in the kernel, potentially escalating privileges. | |
| Title | Integer overflow in vt(4) CONS_HISTORY ioctl | |
| Weaknesses | CWE-190 | |
| References |
|
Status: PUBLISHED
Assigner: freebsd
Published:
Updated: 2026-06-27T09:25:12.443Z
Reserved: 2026-05-29T20:24:28.615Z
Link: CVE-2026-49416
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-27T11:30:15Z