OpenBSD disclosed a local privilege-escalation vulnerability, tracked as CVE-2026-57589, in its System V semaphore implementation. The bug stems from an integer overflow in the sys_semget() handler that can lead to kernel memory corruption and allow a local user to escalate privileges to root under certain conditions.
A fix was committed to OpenBSD-current, while patches for stable branches were still pending in the reporting cited. The flaw was reportedly identified during the Patch the Planet event focused on AI-assisted vulnerability research, and the same reporting also referenced separate OpenBSD findings affecting IPsec/IPComp, NFS, and the pinsyscall and kbind mechanisms.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Also on June 23, a fix for CVE-2026-57589 was committed to the OpenBSD-current branch. At the time described by the sources, patches for stable branches were still pending and had not yet been backported.
On June 23, a vulnerability later tracked as CVE-2026-57589 was identified and presented during the Patch the Planet event focused on AI-assisted vulnerability research. The flaw affects OpenBSD's System V semaphore implementation and stems from an integer overflow in the sys_semget() handler that can lead to kernel memory corruption and possible local root privilege escalation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.