{"api_version":"1","generated_at":"2026-09-23T16:34:04+00:00","cve":"CVE-2026-58091","urls":{"html":"https://cve.report/CVE-2026-58091","api":"https://cve.report/api/cve/CVE-2026-58091.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-58091","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-58091"},"summary":{"title":"Kernel use-after-free via the SNDCTL_DSP_SYNCSTART ioctl","description":"The implementation of this ioctl attempts to acquire locks on all channels in a sync group.  If locking a channel would block, it releases the sync group list lock and sleeps.  Upon reawakening, it is possible that the sync group structure is freed, but the implementation did not handle this possibility.\n\n On a system with a multiple audio devices, an unprivileged local user can exploit this use-after-free to escalate privileges.","state":"PUBLISHED","assigner":"freebsd","published_at":"2026-08-26 05:18:12","updated_at":"2026-08-27 04:16:42"},"problem_types":["CWE-416","CWE-416 CWE-416: Use After Free"],"metrics":[{"version":"3.1","source":"ADP","type":"DECLARED","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}},{"version":"3.1","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}}],"references":[{"url":"https://security.freebsd.org/advisories/FreeBSD-SA-26:58.sound.asc","name":"https://security.freebsd.org/advisories/FreeBSD-SA-26:58.sound.asc","refsource":"secteam@freebsd.org","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-58091","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58091","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"FreeBSD","product":"FreeBSD","version":"affected 15.1-RELEASE p3 release","platforms":[]},{"source":"CNA","vendor":"FreeBSD","product":"FreeBSD","version":"affected 15.0-RELEASE p13 release","platforms":[]},{"source":"CNA","vendor":"FreeBSD","product":"FreeBSD","version":"affected 14.4-RELEASE p9 release","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Hazley Samsudin of GovTech CSG","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"58091","cve":"CVE-2026-58091","epss":"0.001340000","percentile":"0.031660000","score_date":"2026-08-27","updated_at":"2026-08-28 00:03:39"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}},{"other":{"content":{"id":"CVE-2026-58091","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","timestamp":"2026-08-26T00:00:00+00:00","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-08-27T03:57:06.764Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unknown","modules":["sound"],"product":"FreeBSD","vendor":"FreeBSD","versions":[{"lessThan":"p3","status":"affected","version":"15.1-RELEASE","versionType":"release"},{"lessThan":"p13","status":"affected","version":"15.0-RELEASE","versionType":"release"},{"lessThan":"p9","status":"affected","version":"14.4-RELEASE","versionType":"release"}]}],"credits":[{"lang":"en","type":"finder","value":"Hazley Samsudin of GovTech CSG"}],"datePublic":"2026-08-25T19:45:00.000Z","descriptions":[{"lang":"en","value":"The implementation of this ioctl attempts to acquire locks on all channels in a sync group.  If locking a channel would block, it releases the sync group list lock and sleeps.  Upon reawakening, it is possible that the sync group structure is freed, but the implementation did not handle this possibility.\n\n On a system with a multiple audio devices, an unprivileged local user can exploit this use-after-free to escalate privileges."}],"problemTypes":[{"descriptions":[{"cweId":"CWE-416","description":"CWE-416: Use After Free","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-08-26T04:38:19.487Z","orgId":"63664ac6-956c-4cba-a5d0-f46076e16109","shortName":"freebsd"},"references":[{"tags":["vendor-advisory"],"url":"https://security.freebsd.org/advisories/FreeBSD-SA-26:58.sound.asc"}],"title":"Kernel use-after-free via the SNDCTL_DSP_SYNCSTART ioctl","x_generator":{"engine":"cvelib 1.8.0"}}},"cveMetadata":{"assignerOrgId":"63664ac6-956c-4cba-a5d0-f46076e16109","assignerShortName":"freebsd","cveId":"CVE-2026-58091","datePublished":"2026-08-26T04:38:19.487Z","dateReserved":"2026-06-29T01:40:17.498Z","dateUpdated":"2026-08-27T03:57:06.764Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-26 05:18:12","lastModifiedDate":"2026-08-27 04:16:42","problem_types":["CWE-416","CWE-416 CWE-416: Use After Free"],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-26T00:00:00+00:00","id":"CVE-2026-58091","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"58091","Ordinal":"1","Title":"Kernel use-after-free via the SNDCTL_DSP_SYNCSTART ioctl","CVE":"CVE-2026-58091","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"58091","Ordinal":"1","NoteData":"The implementation of this ioctl attempts to acquire locks on all channels in a sync group.  If locking a channel would block, it releases the sync group list lock and sleeps.  Upon reawakening, it is possible that the sync group structure is freed, but the implementation did not handle this possibility.\n\n On a system with a multiple audio devices, an unprivileged local user can exploit this use-after-free to escalate privileges.","Type":"Description","Title":"Kernel use-after-free via the SNDCTL_DSP_SYNCSTART ioctl"}]}}}