MNBSD-2026-8: Local privilege escalation via execve()

Severity: Unknown

Affected Package: kernel

Summary: Local privilege escalation via execve()

Description

An operator precedence bug in the kernel results in a scenario where a buffer overflow causes attacker-controlled data to overwrite adjacent execve(2) argument buffers. The bug may be exploitable by an unprivileged user to obtain superuser privileges.

Affected Versions

kernel

Recommendations

No specific recommendations provided.

References

Additional Information

Aliases: CVE-2026-7270

Published: April 29, 2026
Last Modified: April 29, 2026