Research / Community / Competition

Achievements.

Research records / 09Individual records / 34

Notable vulnerability research

Findings disclosed through coordinated, evidence-driven research.

01 / 062026.09.29FreeBSD / kqueue(2)Published

CVE-2026-58099

Use-after-free in kqueue copy-on-fork marker handling

A race in kqueue copy-on-fork marker handling could access freed kernel memory, potentially allowing an unprivileged local user to escalate privileges.

Advisory
FreeBSD-SA-26:65.kqueue
Credit
Reo Shiseki / Mark Johnston
Affected
FreeBSD 15.1
Patched
FreeBSD 15.1-RELEASE-p4
FreeBSD Security Advisory
02 / 062026.09.29FreeBSD / kqueue(2)Published

CVE-2026-58100

Out-of-bounds read in kqueue copy-on-fork descriptor handling

A race in kqueue copy-on-fork descriptor handling could read beyond the child's file descriptor table, potentially allowing an unprivileged local user to escalate privileges.

Advisory
FreeBSD-SA-26:65.kqueue
Credit
Reo Shiseki / Mark Johnston
Affected
FreeBSD 15.1
Patched
FreeBSD 15.1-RELEASE-p4
FreeBSD Security Advisory
03 / 062026.09.29FreeBSD / semop(2)Published

CVE-2026-58098

Kernel heap out-of-bounds access in semop(2)

Semaphore identifier reuse after sequence-number wraparound could cause semop(2) to access kernel heap memory out of bounds, potentially allowing an unprivileged local user to escalate privileges.

Advisory
FreeBSD-SA-26:64.sysvsem
Credit
Reo Shiseki / Andrew Griffiths
Affected
All supported FreeBSD versions at disclosure
Patched
FreeBSD 15.1-RELEASE-p4 / 15.0-RELEASE-p14 / 14.5-RELEASE-p1 / 14.4-RELEASE-p10
FreeBSD Security Advisory
04 / 062026.09.13Ant / Linux KVM sandboxPublished

GHSA-v34g-p68p-f5cm

Linux KVM sandbox escape through UDP and 9p memory corruption

A guest-kernel UDP heap overflow could be chained with an integer overflow in the host 9p backend to escape Ant's Linux x86-64 KVM sandbox and execute attacker-controlled commands in the host Ant process.

Severity
High / 8.8 (CVSS 4.0)
Affected
>= 0.12.0.1780342116, < 15.1.6aee72e4.0
Patched
15.1.6aee72e4.0
Verified
Ant 15.1.33d3a51a.0 / Linux x86-64 / KVM
Credit
n01e0
GitHub Security Advisory
05 / 062026.08.25FreeBSD / ppp(8)Published

CVE-2026-58095

Global buffer overflow in ppp(8) endpoint discriminator formatting

An incorrect length calculation in mp_Enddisc() could allow a malicious PPP peer to overflow a global result buffer through a received multilink endpoint discriminator option.

Advisory
FreeBSD-SA-26:60.ppp
Credit
Reo Shiseki / n01e0
Affected
All supported FreeBSD versions at disclosure
FreeBSD Security Advisory
06 / 062026.08.25FreeBSD / ppp(8)Published

CVE-2026-58096

Out-of-bounds write in ppp(8) endpoint option decoding

Missing minimum-length validation in LcpDecodeConfig() could allow a malicious PPP peer to trigger an out-of-bounds write with an undersized multilink endpoint discriminator option.

Advisory
FreeBSD-SA-26:60.ppp
Credit
Reo Shiseki / n01e0
Affected
All supported FreeBSD versions at disclosure
FreeBSD Security Advisory
View all research records

Record / 2019 — 2026

Challenge design, instruction, speaking, community work, and competition results.

2026

2025

2024

2023

2022

2021

2020

2019