Stack-based Buffer Overflow Affecting freebsd package, versions [,13.5.0-p11)[14.3.0,14.3.0-p10)[14.4.0,14.4.0-p1)[15.0.0,15.0.0-p5)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
2.49% (84th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-FREEBSD-15812211
  • published29 Mar 2026
  • disclosed26 Mar 2026
  • creditNicholas Carlini

Introduced: 26 Mar 2026

CVE-2026-4747  (opens in a new tab)
CWE-121  (opens in a new tab)

How to fix?

Upgrade freebsd to version 13.5.0-p11, 14.3.0-p10, 14.4.0-p1, 15.0.0-p5 or higher.

Overview

Affected versions of this package are vulnerable to Stack-based Buffer Overflow in the RPCSEC_GSS packet validation process. An attacker can execute arbitrary code in kernel or user space by sending specially crafted packets to the affected server. This is only exploitable if the kgssapi.ko module is loaded in the kernel or if an application has librpcgss_sec loaded and runs an RPC server.

CVSS Base Scores

version 4.0
version 3.1