{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/netbsd/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7,"id":"CVE-2026-53996"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["NetBSD"],"_cs_severities":["high"],"_cs_tags":["privilege-escalation","netbsd","kernel-vulnerability"],"_cs_type":"advisory","_cs_vendors":["NetBSD"],"content_html":"\u003cp\u003eThe NetBSD hdaudio(4) driver (sys/dev/hdaudio/hdaudio.c) contains a critical missing access control vulnerability, tracked as CVE-2026-53996. The vulnerability stems from the absence of required access checks when interacting with /dev/hdaudioN device nodes. This flaw allows an unprivileged local user to invoke the HDAUDIO_FGRP_SETCONFIG ioctl, which should be restricted. By exploiting this lack of access control, an attacker can initiate a race condition between the stream_stop() and stream_disestablish() functions during hdafg_detach(). This race condition leads to a use-after-free scenario where a latched DMA interrupt dereferences a callback pointer that has already been freed. Depending on the memory state, this can result in a denial of service via kernel panic or, in specific conditions, local kernel privilege escalation. Defenders should prioritize patching systems running NetBSD kernels that utilize the hdaudio driver.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker establishes a low-privileged local session on a NetBSD target.\u003c/li\u003e\n\u003cli\u003eAttacker identifies available audio device nodes at /dev/hdaudio*.\u003c/li\u003e\n\u003cli\u003eAttacker opens a targeted /dev/hdaudioN device node without specific user permissions.\u003c/li\u003e\n\u003cli\u003eAttacker launches a multi-threaded process to interact with the HDAUDIO_FGRP_SETCONFIG ioctl.\u003c/li\u003e\n\u003cli\u003eThread 1 repeatedly invokes the HDAUDIO_FGRP_SETCONFIG ioctl to trigger detach procedures.\u003c/li\u003e\n\u003cli\u003eThread 2 maintains active DMA and IRQs, forcing a race condition during the hdafg_detach() call.\u003c/li\u003e\n\u003cli\u003eThe kernel dereferences a freed callback pointer due to the race between stream_stop() and stream_disestablish().\u003c/li\u003e\n\u003cli\u003eSystem crashes (DoS) or attacker achieves kernel-mode code execution (Privilege Escalation).\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-53996 allows any local user on a NetBSD system to cause a system-wide kernel panic, disrupting service availability. Furthermore, the use-after-free vulnerability provides a vector for local privilege escalation, potentially allowing an attacker to gain kernel-level execution rights, bypass filesystem permissions, and gain full control of the affected host.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eApply the vendor-provided patch for CVE-2026-53996 to all NetBSD systems.\u003c/li\u003e\n\u003cli\u003eAudit local system access to determine if unprivileged users have legitimate business needs to access /dev/hdaudio* device nodes.\u003c/li\u003e\n\u003cli\u003eImplement Udev-style rules or manual permission management to restrict read/write access to /dev/hdaudio* to authorized users or groups only.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-12T14:46:36Z","date_published":"2026-08-12T14:46:36Z","id":"https://feed.craftedsignal.io/briefs/2026-08-netbsd-hdaudio-priv-esc/","summary":"An unprivileged local attacker can trigger a use-after-free condition in the NetBSD hdaudio(4) driver by exploiting a missing access check on /dev/hdaudioN nodes to invoke the HDAUDIO_FGRP_SETCONFIG ioctl.","title":"NetBSD Local Privilege Escalation via hdaudio Driver","url":"https://feed.craftedsignal.io/briefs/2026-08-netbsd-hdaudio-priv-esc/"}],"language":"en","title":"CraftedSignal Threat Feed - NetBSD","version":"https://jsonfeed.org/version/1.1"}