CVE-2026-4747
published 2026-03-26CVE-2026-4747: Each RPCSEC_GSS data packet is validated by a routine which checks a signature in the packet. This routine copies a portion of the packet into a stack buffer…
PriorityP264high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.11%
64.6th percentile
Each RPCSEC_GSS data packet is validated by a routine which checks a signature in the packet. This routine copies a portion of the packet into a stack buffer, but fails to ensure that the buffer is sufficiently large, and a malicious client can trigger a stack overflow. Notably, this does not require the client to authenticate itself first.
As kgssapi.ko's RPCSEC_GSS implementation is vulnerable, remote code execution in the kernel is possible by an authenticated user that is able to send packets to the kernel's NFS server while kgssapi.ko is loaded into the kernel.
In userspace, applications which have librpcgss_sec loaded and run an RPC server are vulnerable to remote code execution from any client able to send it packets. We are not aware of any such applications in the FreeBSD base system.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| freebsd | freebsd | >= 13.5-RELEASE < p11 | p11 |
| freebsd | freebsd | >= 14.3-RELEASE < p10 | p10 |
| freebsd | freebsd | >= 14.4-RELEASE < p1 | p1 |
| freebsd | freebsd | >= 15.0-RELEASE < p5 | p5 |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerability is exploitable WITHOUT prior authentication — malicious RPCSEC_GSS packets can trigger the stack overflow before any client authentication handshake completes. Monitor NFS/RPC traffic for oversized or malformed RPCSEC_GSS signature fields from unauthenticated sources. ↗
- →Exposure is conditional on kgssapi.ko being loaded. Audit kernel module load state (`kldstat`) on NFS servers; if kgssapi.ko is present and the system is unpatched, treat as actively exploitable from the network. ↗
- →Userspace RPC daemons linked against librpcgss_sec are independently vulnerable to RCE from any network client, regardless of kgssapi.ko state. Enumerate processes with librpcgss_sec in their loaded libraries (e.g., via `procstat -v` or `lsof`). ↗
- →The attack surface is the kernel NFS server's RPCSEC_GSS packet validation routine. Alert on unexpected kernel crashes or stack-smashing canary trips (e.g., via kernel panic logs) on FreeBSD NFS servers, which may indicate exploitation attempts. ↗
- →Patch verification: confirm Git commit hashes for each branch are present (e.g., 1b00fdc1f3cd for stable/15, 4ec1b6213463 for releng/15.0) using `git rev-list` to validate patched state before and after remediation. ↗
- ·NVD frames kernel RCE as requiring the attacker to be able to send packets while kgssapi.ko is loaded, whereas Anthropic's red-team account describes it as 'full root for an unauthenticated attacker from anywhere on the internet.' Defenders should treat the pre-auth stack overflow as the confirmed primitive and scope impact conservatively to network-reachable NFS servers with kgssapi.ko loaded. ↗
- ·All supported FreeBSD versions are affected (13.x, 14.x, 15.x). Corrections were committed 2026-03-26; systems not yet updated to the corrected stable/releng branches remain vulnerable. ↗
- ·No workaround exists other than unloading kgssapi.ko (which disables Kerberos-based NFS auth). Userspace daemons linked with librpcgss_sec have no equivalent mitigation short of stopping the daemon. ↗
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h63x-7924-m7qf: Each RPCSEC_GSS data packet is validated by a routine which checks a signature in the packet
ghsa_unreviewed·2026-03-26
CVE-2026-4747 [HIGH] CWE-121 GHSA-h63x-7924-m7qf: Each RPCSEC_GSS data packet is validated by a routine which checks a signature in the packet
Each RPCSEC_GSS data packet is validated by a routine which checks a signature in the packet. This routine copies a portion of the packet into a stack buffer, but fails to ensure that the buffer is sufficiently large, and a malicious client can trigger a stack overflow. Notably, this does not require the client to authenticate itself first.
As kgssapi.ko's RPCSEC_GSS implementation is vulnerable, remote code execution in the kernel is possible by an authenticated user that is able to send packets to the kernel's NFS server while kgssapi.ko is loaded into the kernel.
In userspace, applications which have librpcgss_sec loaded and run an RPC server are vulnerable to remote code execution from any client able to send it packets. We are not aware of any such applications in the FreeBSD base s
BSD
FreeBSD-SA-26:08.rpcsec_gss: Remote code execution via RPCSEC_GSS packet validation
bsd_advisories·2026-03-26·CVSS 8.8
CVE-2026-4747 [HIGH] FreeBSD-SA-26:08.rpcsec_gss: Remote code execution via RPCSEC_GSS packet validation
FreeBSD-SA-26:08.rpcsec_gss Security Advisory
The FreeBSD Project
Topic: Remote code execution via RPCSEC_GSS packet validation
Category: core
Module: rpcsec_gss
Announced: 2026-03-26
Credits: Nicholas Carlini using Claude, Anthropic
Affects: All supported versions of FreeBSD.
Corrected: 2026-03-26 01:25:23 UTC (stable/15, 15.0-STABLE)
2026-03-26 01:11:20 UTC (releng/15.0, 15.0-RELEASE-p5)
2026-03-26 01:28:47 UTC (stable/14, 14.4-STABLE)
2026-03-26 01:14:55 UTC (releng/14.4, 14.4-RELEASE-p1)
2026-03-26 01:16:01 UTC (releng/14.3, 14.3-RELEASE-p10)
2026-03-26 01:30:12 UTC (stable/13, 13.5-STABLE)
2026-03-26 01:34:10 UTC (releng/13.5, 13.5-RELEASE-p11)
CVE Name: CVE-2026-4747
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security
No detection rules found.
No public exploits indexed.
Hackernews
New "Bad Epoll" Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits Android
blogs_hackernews·2026-07-04·CVSS 7.8
CVE-2026-46242 [HIGH] New "Bad Epoll" Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits Android
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## New "Bad Epoll" Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits Android
A newly disclosed Linux kernel flaw called Bad Epoll (CVE-2026-46242) lets an ordinary user with no special access take full control of a machine as root. It affects Linux desktops, servers, and Android, and a fix is out.
Bad Epoll sits in the same small stretch of kernel code where Anthropic's most powerful AI model, Mythos , recently found a different bug.
The AI caught one flaw and missed this one. A researcher, Jaeyoung Chung, found it and built a working attack.
## How the Bug Works
Epoll is a standard Linux feature that lets a progra
Hackernews
Anthropic Releases Claude Fable 5, Its Most Powerful AI Yet, With Cyber Safeguards
blogs_hackernews·2026-06-10
CVE-2026-4747 Anthropic Releases Claude Fable 5, Its Most Powerful AI Yet, With Cyber Safeguards
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Anthropic Releases Claude Fable 5, Its Most Powerful AI Yet, With Cyber Safeguards
On June 9, Anthropic released Claude Fable 5 , the most capable model it has ever made, generally available. It also did something unusual: it shipped one model as two products, split not by capability but by a layer of safety classifiers.
Fable 5 goes to the public. Its twin, Claude Mythos 5, the same underlying model with the cyber safeguards lifted, stays locked to a vetted group of cyber defenders and critical infrastructure operators.
Anthropic calls Mythos 5 the strongest cybersecurity model in the world.
The practical difference is th
2026-03-26
Published