Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 11 Sep 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NetBSD contains an information disclosure vulnerability in mm_open() within sys/dev/mm.c that allows unprivileged local users to obtain real kernel virtual addresses by opening world-accessible devices such as /dev/null or /dev/zero, which incorrectly receive the PK_KMEM process flag. Attackers can exploit this misconfigured flag to bypass the CANSEE_KPTR obfuscation mechanism and read kernel virtual addresses for sensitive kernel structures including struct proc, kauth_cred, filedesc, and vmspace via sysctl KERN_PROC queries. | |
| Title | NetBSD mm_open() PK_KMEM Flag Kernel Pointer Information Disclosure | |
| Weaknesses | CWE-732 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-11T13:50:32.448Z
Reserved: 2026-06-25T18:48:00.281Z
Link: CVE-2026-57843
No data.
Status : Received
Published: 2026-09-11T14:17:28.067
Modified: 2026-09-11T14:17:28.067
Link: CVE-2026-57843
No data.
OpenCVE Enrichment
No data.
-
CWE-732
Incorrect Permission Assignment for Critical Resource