CVE-2026-57589

Severity CVSS v4.0:
Pending analysis
Type:
CWE-416 Use After Free
Publication date:
25/06/2026
Last modified:
10/07/2026

Description

sys/kern/sysv_sem.c in OpenBSD through 7.9 has a use-after-free allowing local privilege escalation to root. This is a context switch use-after-free after tsleep in sys_semget().

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:openbsd:openbsd:*:*:*:*:*:*:*:* 7.9 (including)