CVE-2026-45252
When a fusefs file system implements extended attributes, the kernel may send a FUSE_LISTXATTR message to the userspace daemon to retrieve the list of extended attributes for a given file. The FUSE protocol requires the daemon to return a packed list of NUL-terminated strings. The fusefs kernel module calls strlen() on this daemon-supplied buffer without first verifying that the entire list is NUL-terminated.
If a malicious daemon sends a non-NUL-terminated list, the fusefs kernel module may read beyond the end of one heap-allocated buffer and potentially write beyond the end of a second buffer. A malicious daemon could disclose up to 253 bytes of kernel heap memory, or it could inject up to 250 attacker-controlled bytes into unallocated kernel heap space.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:H
- Puntuación base: 5.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.44%
- Percentil entre todas las CVEs puntuadas: 36
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-122
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-45252",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-45252",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-05-21T13:46:56.283986Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.5,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "HIGH",
"confidentialityImpact": "LOW"
},
"impactScore": 4.2,
"exploitabilityScore": 1.2
}
]
},
"affected": [
{
"source": "secteam@freebsd.org",
"affectedData": [
{
"vendor": "FreeBSD",
"modules": [
"fusefs"
],
"product": "FreeBSD",
"versions": [
{
"status": "affected",
"version": "15.0-RELEASE",
"lessThan": "p9",
"versionType": "release"
},
{
"status": "affected",
"version": "14.4-RELEASE",
"lessThan": "p5",
"versionType": "release"
},
{
"status": "affected",
"version": "14.3-RELEASE",
"lessThan": "p14",
"versionType": "release"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2026-05-21T10:16:26.157",
"references": [
{
"url": "https://security.freebsd.org/advisories/FreeBSD-SA-26:20.fusefs.asc",
"tags": [
"Vendor Advisory"
],
"source": "secteam@freebsd.org"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "secteam@freebsd.org",
"description": [
{
"lang": "en",
"value": "CWE-122"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "When a fusefs file system implements extended attributes, the kernel may send a FUSE_LISTXATTR message to the userspace daemon to retrieve the list of extended attributes for a given file. The FUSE protocol requires the daemon to return a packed list of NUL-terminated strings. The fusefs kernel module calls strlen() on this daemon-supplied buffer without first verifying that the entire list is NUL-terminated.\n\nIf a malicious daemon sends a non-NUL-terminated list, the fusefs kernel module may read beyond the end of one heap-allocated buffer and potentially write beyond the end of a second buffer. A malicious daemon could disclose up to 253 bytes of kernel heap memory, or it could inject up to 250 attacker-controlled bytes into unallocated kernel heap space."
},
{
"lang": "es",
"value": "Cuando un sistema de archivos fusefs implementa atributos extendidos, el kernel puede enviar un mensaje FUSE_LISTXATTR al demonio de espacio de usuario para recuperar la lista de atributos extendidos para un archivo dado. El protocolo FUSE requiere que el demonio devuelva una lista empaquetada de cadenas terminadas en NUL. El módulo del kernel fusefs llama a strlen() en este búfer proporcionado por el demonio sin verificar primero que toda la lista esté terminada en NUL.\n\nSi un demonio malicioso envía una lista no terminada en NUL, el módulo del kernel fusefs puede leer más allá del final de un búfer asignado en el montón y potencialmente escribir más allá del final de un segundo búfer. Un demonio malicioso podría divulgar hasta 253 bytes de memoria del montón del kernel, o podría inyectar hasta 250 bytes controlados por el atacante en espacio de montón del kernel no asignado."
}
],
"lastModified": "2026-07-23T16:10:00.137",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:freebsd:freebsd:14.3:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9DC7C54E-58AF-4ADE-84AF-0EF0F325E20E"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:14.3:p1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D3D22B8C-36CF-4800-9673-0B0240558BDD"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:14.3:p10:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7296F5AA-F8C1-4277-A4EE-C2B24073A320"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:14.3:p11:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C30E4A9C-0594-4F40-92B3-26CB9AA85AE9"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:14.3:p12:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9F83F91B-587A-433C-99DB-0D63E267FF16"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:14.3:p13:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "44B9C2FC-756E-459F-8E68-C2C2B8C258AC"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:14.3:p2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "242FA2A8-5D7D-4617-A411-2651FF3A3E4C"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:14.3:p3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "40573F60-F3B7-4AEC-846A-B08E5B7D9D00"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:14.3:p4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1FB832CE-0A98-44A2-8BAC-CD38A64279B6"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:14.3:p5:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9A785F8E-C218-41AE-8D57-BF06DDAEF7CB"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:14.3:p6:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C3909FDD-B2A2-45B6-A40B-1D303A717F15"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:14.3:p7:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "720597A2-F181-46E1-8A0D-097E17ADC4FB"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:14.3:p8:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DC8A75D0-148A-427A-9783-45477EABED21"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:14.3:p9:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F5D39FC9-6DBA-46C8-BB80-A6188E6A8527"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:14.4:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8F3856BE-666F-4FA1-A6AD-FE179CEBF1E4"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:14.4:p1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D9CC0037-3282-42C3-80D8-F6C1D43B9332"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:14.4:p2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1EADA828-3C20-43C0-A0CA-3AC7D7F23DBD"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:14.4:p3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "53D73FD2-4B06-47D3-BA2A-4363E9DE3565"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:14.4:p4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D726890B-E679-43A9-A211-D5C05BBE3941"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:14.4:rc1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0342A715-E211-4AF6-97ED-32EB9EBB947D"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:15.0:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "368CFE5D-C5C2-42AF-AAF4-28DFE1A59C3B"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:15.0:p1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AA4AAA57-70A7-4717-ACF2-A253E757FF2C"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:15.0:p2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E24ABFA6-4D12-4DE5-832B-438502C7D188"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:15.0:p3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C1C9869C-494B-4628-9AA3-4AA5B989C377"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:15.0:p4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "002AA2FE-C7BA-471A-9434-0E56A878ACBF"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:15.0:p5:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B187670D-E3A2-4A0D-A653-982F8B447E78"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:15.0:p6:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "047E7EE9-FB51-4CF2-A8BE-484BFD819565"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:15.0:p7:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2C9768AE-9954-4B2A-9525-D7D4942406E7"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:15.0:p8:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F8B9EF55-3755-452A-B067-043803099B22"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "secteam@freebsd.org"
}