Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 11 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 11 Sep 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NetBSD contains a use-after-free and double-free vulnerability in msg_recv_copyin() within the COMPAT_NETBSD32 compatibility layer due to a missing return statement before the cleanup label on the success path. Any local user able to execute a 32-bit binary on a 64-bit NetBSD system can trigger a kernel panic or memory corruption by calling recvmsg() with msg_iovlen between 9 and IOV_MAX, causing the kernel to access a freed iovec buffer and subsequently free the same allocation a second time. | |
| Title | NetBSD COMPAT_NETBSD32 Double Free / Use-After-Free via recvmsg() msg_iovlen | |
| Weaknesses | CWE-415 CWE-416 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-11T14:56:18.726Z
Reserved: 2026-06-25T18:48:00.281Z
Link: CVE-2026-57842
Updated: 2026-09-11T14:56:15.374Z
Status : Received
Published: 2026-09-11T14:17:27.873
Modified: 2026-09-11T15:17:02.313
Link: CVE-2026-57842
No data.
OpenCVE Enrichment
Updated: 2026-09-11T16:00:06Z