{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3onetbsdnetbsd/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:o:netbsd:netbsd:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7,"id":"CVE-2026-57842"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["NetBSD"],"_cs_severities":["high"],"_cs_tags":["kernel","vulnerability","privilege-escalation"],"_cs_type":"advisory","_cs_vendors":["NetBSD"],"content_html":"\u003cp\u003eCVE-2026-57842 is a critical vulnerability within the COMPAT_NETBSD32 compatibility layer of the NetBSD kernel. The issue originates in the msg_recv_copyin() function, where a missing return statement on the success path causes the kernel to retain a reference to an iovec buffer that has already been freed. When a local attacker executes a 32-bit binary on a 64-bit NetBSD system, they can invoke the recvmsg() system call with a msg_iovlen value set between 9 and IOV_MAX. This sequence triggers the kernel to access the previously freed iovec buffer and subsequently attempt to free the same memory allocation a second time. This memory corruption vulnerability represents a significant risk for local privilege escalation and system instability, as it allows for controlled disruption of kernel memory management.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows an unprivileged local user to trigger kernel panics, causing denial of service. Furthermore, the memory corruption primitive provides a pathway for local privilege escalation, potentially allowing a standard user to gain administrative control over the affected system. The vulnerability specifically affects 64-bit NetBSD environments that have the COMPAT_NETBSD32 compatibility layer enabled.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eDetection and mitigation should focus on identifying unauthorized execution of 32-bit binaries or suspicious kernel behavior.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAudit systems for the presence and necessity of the COMPAT_NETBSD32 compatibility layer and disable if not required for legacy support.\u003c/li\u003e\n\u003cli\u003eMonitor for unexpected system calls or frequent kernel-level crashes associated with 32-bit binary execution.\u003c/li\u003e\n\u003cli\u003ePatch the NetBSD kernel immediately once the vendor provides the security update addressing CVE-2026-57842.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-11T15:13:40Z","date_published":"2026-09-11T15:13:40Z","id":"https://feed.craftedsignal.io/briefs/2026-09-netbsd-uaf/","summary":"A use-after-free and double-free vulnerability in the NetBSD kernel's COMPAT_NETBSD32 layer allows local users to trigger memory corruption or kernel panics via crafted recvmsg system calls.","title":"CVE-2026-57842: Kernel Use-After-Free in NetBSD COMPAT_NETBSD32 Layer","url":"https://feed.craftedsignal.io/briefs/2026-09-netbsd-uaf/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:o:netbsd:netbsd:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}