FreeBSD disclosed CVE-2026-4747 in advisory FreeBSD-SA-26:08.rpcsec_gss, warning that improper bounds checking in RPCSEC_GSS packet-signature validation can copy attacker-controlled data into a fixed stack buffer and trigger a stack overflow. The bug affects all supported FreeBSD versions and can be exploited by an unauthenticated client. In the kernel, exploitation is possible when kgssapi.ko is loaded and the system is running an NFS server with RPCSEC_GSS enabled; in userspace, RPC servers linked against librpcsec_gss are also exposed, although FreeBSD said it was not aware of vulnerable base-system applications in that category.
Independent technical write-ups tied the flaw to svc_rpc_gss_validate in the RPC/NFS path, describing how a crafted RPCSEC_GSS credential length can overflow a 128-byte stack buffer and potentially corrupt saved control data, leading to denial of service or kernel-mode remote code execution. The reports said the issue is reachable over the network, commonly via NFS on TCP port 2049, and could result in full system compromise if exploited successfully. FreeBSD released patches for supported stable and release branches and said there is no practical workaround beyond avoiding deployments where kgssapi.ko is loaded.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Additional public analysis assessed the bug as highly exploitable on FreeBSD 14.x NFS systems, citing predictable kernel addresses, limited stack protection, and ROP as a plausible route to kernel compromise. The write-ups recommended bounds checking, stronger stack-protector settings, kernel ASLR, and auditing similar RPC handling paths.
Independent GitHub write-ups analyzed the flaw as a stack-based buffer overflow in FreeBSD's svc_rpc_gss_validate function, where attacker-controlled credential length can cause memcpy to overrun a fixed 128-byte stack buffer. These analyses characterized the issue as remotely reachable via crafted RPCSEC_GSS/NFS requests and potentially leading to denial of service or kernel-level remote code execution.
FreeBSD disclosed that kernel exploitation is possible when kgssapi.ko is loaded and an NFS server is running with RPCSEC_GSS support, allowing unauthenticated remote code execution. It also noted that RPC servers linked with librpcsec_gss are vulnerable in userspace, though it was not aware of affected base-system applications.
The FreeBSD Project published security advisory FreeBSD-SA-26:08.rpcsec_gss for CVE-2026-4747, describing a remote code execution flaw caused by improper bounds checking in RPCSEC_GSS packet validation. FreeBSD released fixes for supported stable and release branches on the same day and said no workaround was available beyond avoiding systems with kgssapi.ko loaded.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcefreebsd.org
Open sourcesecurity.freebsd.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.