What is CVE-2026-49423?
CVE-2026-49423 is a vulnerability in FreeBSD's Kernel TLS (kTLS) implementation. When decrypting TLS 1.2 CBC records, an incorrect iovec index increment leads to uninitialized entries in the iovec array, potentially causing data leakage or system instability. Affected systems should apply the vendor patch immediately.
Azərbaycanca: CVE-2026-49423, FreeBSD nüvəsinin Kernel TLS (kTLS) implementasiyasında aşkar edilmiş boşluqdur. TLS 1.2 CBC qeydlərinin şifrəsinin açılması zamanı iovec massivində səhv indeks artımı baş verir, bu da istifadə olunmamış iovec elementlərinə səbəb olur. Təsirə məruz qalan sistemlərdə potensial məlumat sızması və ya nasazlıq riski var, yamaq tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-119
FAQ2
Which FreeBSD component is affected by CVE-2026-49423?
The vulnerability is found in FreeBSD's Kernel TLS (kTLS) implementation.
What risks arise from exploiting CVE-2026-49423?
Uninitialized iovec entries may cause potential data leakage or system instability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.