Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 19 May 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Netbsd
Netbsd src |
|
| Vendors & Products |
Netbsd
Netbsd src |
Mon, 18 May 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 18 May 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NetBSD prior to commit ec8451e contains a signed integer overflow vulnerability in the cryptodev_op() function in sys/opencrypto/cryptodev.c where the local variable iov_len is declared as a signed int but assigned from an unsigned cop->dst_len value, causing undefined behavior when cop->dst_len exceeds INT_MAX. A local attacker with access to /dev/crypto and a compression session type can exploit this vulnerability by providing a dst_len value exceeding INT_MAX to trigger a kernel panic through NULL pointer dereference when CONFIG_SVS is disabled and corrupted UIO pointer arithmetic. | |
| Title | NetBSD Signed Integer Overflow in cryptodev_op via cryptodev.c | |
| Weaknesses | CWE-190 CWE-476 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-18T18:58:07.838Z
Reserved: 2026-03-16T18:11:41.759Z
Link: CVE-2026-32849
Updated: 2026-05-18T18:57:13.890Z
Status : Deferred
Published: 2026-05-18T18:17:23.377
Modified: 2026-06-17T10:36:26.570
Link: CVE-2026-32849
No data.
OpenCVE Enrichment
Updated: 2026-05-19T08:18:51Z