All CVEs
Vulnerability intelligence

CVE-2026-49420

FreeBSD FreeBSD CWE-121

The RTSP handler in libalias rewrote outgoing packets into a fixed-length stack buffer without checking whether the rewritten data fit in the buffer, or whether the result fit back in the original packet. A host sending crafted RTSP traffic from inside a NAT gateway using libalias can overflow a stack buffer, potentially achieving remote code execution in the kernel (when using ipfw(4) NAT) or in the natd(8) process (which generally runs as the root user).

CVSS Score
8.8
High
EPSS — Exploit Probability
0.4%
Riskier than 34% of all CVEs · checked 2026-10-03
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
unknown
Check vendor advisories
NVD entry

1 article across 1 outlet · first covered Jul 6, 2026 · latest Jul 6, 2026

Coverage timeline

Related CVEs — FreeBSD