cbcvebase.
CVE-2026-4747
published 2026-03-26

CVE-2026-4747: Each RPCSEC_GSS data packet is validated by a routine which checks a signature in the packet. This routine copies a portion of the packet into a stack buffer…

PriorityP264high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.11%
64.6th percentile
Each RPCSEC_GSS data packet is validated by a routine which checks a signature in the packet. This routine copies a portion of the packet into a stack buffer, but fails to ensure that the buffer is sufficiently large, and a malicious client can trigger a stack overflow. Notably, this does not require the client to authenticate itself first. As kgssapi.ko's RPCSEC_GSS implementation is vulnerable, remote code execution in the kernel is possible by an authenticated user that is able to send packets to the kernel's NFS server while kgssapi.ko is loaded into the kernel. In userspace, applications which have librpcgss_sec loaded and run an RPC server are vulnerable to remote code execution from any client able to send it packets. We are not aware of any such applications in the FreeBSD base system.

Affected

8 ranges
VendorProductVersion rangeFixed in
freebsdfreebsd——
freebsdfreebsd——
freebsdfreebsd——
freebsdfreebsd——
freebsdfreebsd>= 13.5-RELEASE < p11p11
freebsdfreebsd>= 14.3-RELEASE < p10p10
freebsdfreebsd>= 14.4-RELEASE < p1p1
freebsdfreebsd>= 15.0-RELEASE < p5p5

Detection & IOCsextracted from sources · hover to see the quote

urlhttps://security.FreeBSD.org/patches/SA-26:08/rpcsec_gss.patch↗
hash1b00fdc1f3cd↗
hash4ec1b6213463↗
hashe5ed09ffd592↗
hash7ea03a4238e8↗
hashb6ce88ab9a5f↗
hash99ec7f9b9e48↗
hashc4f53a1adbd4↗
filenamekgssapi.ko↗
filenamerpcsec_gss.patch↗
  • →The vulnerability is exploitable WITHOUT prior authentication — malicious RPCSEC_GSS packets can trigger the stack overflow before any client authentication handshake completes. Monitor NFS/RPC traffic for oversized or malformed RPCSEC_GSS signature fields from unauthenticated sources. ↗
  • →Exposure is conditional on kgssapi.ko being loaded. Audit kernel module load state (`kldstat`) on NFS servers; if kgssapi.ko is present and the system is unpatched, treat as actively exploitable from the network. ↗
  • →Userspace RPC daemons linked against librpcgss_sec are independently vulnerable to RCE from any network client, regardless of kgssapi.ko state. Enumerate processes with librpcgss_sec in their loaded libraries (e.g., via `procstat -v` or `lsof`). ↗
  • →The attack surface is the kernel NFS server's RPCSEC_GSS packet validation routine. Alert on unexpected kernel crashes or stack-smashing canary trips (e.g., via kernel panic logs) on FreeBSD NFS servers, which may indicate exploitation attempts. ↗
  • →Patch verification: confirm Git commit hashes for each branch are present (e.g., 1b00fdc1f3cd for stable/15, 4ec1b6213463 for releng/15.0) using `git rev-list` to validate patched state before and after remediation. ↗
  • ·NVD frames kernel RCE as requiring the attacker to be able to send packets while kgssapi.ko is loaded, whereas Anthropic's red-team account describes it as 'full root for an unauthenticated attacker from anywhere on the internet.' Defenders should treat the pre-auth stack overflow as the confirmed primitive and scope impact conservatively to network-reachable NFS servers with kgssapi.ko loaded. ↗
  • ·All supported FreeBSD versions are affected (13.x, 14.x, 15.x). Corrections were committed 2026-03-26; systems not yet updated to the corrected stable/releng branches remain vulnerable. ↗
  • ·No workaround exists other than unloading kgssapi.ko (which disables Kerberos-based NFS auth). Userspace daemons linked with librpcgss_sec have no equivalent mitigation short of stopping the daemon. ↗
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.