CVE-2026-49417 is a use-after-free vulnerability in the FreeBSD sound(4) mmap path affecting /dev/dsp mappings. The audio buffer backing an existing mapping can be freed when the device is closed even though the mapping remains valid. That stale mapping can then continue to reference memory that has been returned to the kernel allocator and potentially reused for other kernel objects. As a result, a local user with access to /dev/dsp can continue to access freed kernel memory through the lingering mapping, creating a kernel-space read/write primitive.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Single-file local FreeBSD kernel privilege-escalation exploit in C. The code targets the OSS /dev/dsp device and appears to exploit a stale/shared kernel buffer mapping condition combined with controlled kernel stack/thread state associated with nanosleep(). Repository structure is minimal: one entry-point file, exp.c. Exploit flow: it resolves the running kernel base with kldstat(1) and the sys_nanosleep symbol with kldsym(), computes hardcoded gadget addresses relative to the kernel base, and builds executable userland shellcode. That shellcode runs in kernel context and directly edits the current process credentials to set UID/GID values to 0, effectively making the process root. Before executing shellcode, the exploit prepares a mini ROP chain to disable SMEP by writing a modified CR4 value, allowing execution of attacker-controlled code from user memory, then later restores the original CR4. To trigger the vulnerability, the exploit opens /dev/dsp repeatedly, configures fragments with SNDCTL_DSP_SETFRAGMENT, queries buffer geometry with SNDCTL_DSP_GETOSPACE, mmaps the device buffers, and fills them with a marker value. It then closes the file descriptors while retaining the mappings, suggesting reliance on stale mappings or freed/reused kernel-backed pages. In parallel, it creates 1200 pthreads with attacker-controlled stacks; each thread enters nanosleep() with crafted timespec values embedding thread-specific markers in tv_nsec. The exploit scans the stale mapped pages for those markers and for pointers into kernel text, identifying reused pages containing kernel stack data. Once it finds a page containing the expected sys_nanosleep return address, it overwrites that stack slot with a ROP chain: pop rax; ret -> CR4_NOSMEP -> mov cr4, rax; ret -> shellcode address. After the corrupted kernel thread resumes, the shellcode should execute in kernel mode, patch credentials, restore CR4, and return. The userland loop polls geteuid() until it becomes 0, verifies UID/EUID, and execs /bin/sh. Overall, this is a real, operational local privilege-escalation exploit with a built-in payload, but it is highly version-specific due to fixed gadget offsets and CR4 assumptions.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.