


Perceptive Security
SOC/SIEM Consultancy

When processing the header of an incoming message, libnv failed to properly validate the message size.
The lack of validation allows a malicious program to wri…
Published:
29 april 2026 om 22:00:00
Alert date:
30 april 2026 om 17:05:34
Source:
nvd.nist.gov
Operating Systems
CVE-2026-35547 affects the libnv library in FreeBSD systems. When processing incoming message headers, libnv fails to properly validate message size. This validation failure allows malicious programs to write outside heap allocation bounds. The vulnerability can trigger system crashes or panics. Unprivileged users may be able to exploit this bug for privilege escalation. This represents a significant security risk for FreeBSD systems using the libnv library.
Technical details
Mitigation steps:
Affected products:
FreeBSD
libnv
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-35547
https://security.freebsd.org/advisories/FreeBSD-SA-26:17.libnv.asc
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
