All findings

CVE-2026-39461, CVE-2026-45252, CVE-2026-45254 high

FreeBSD credits AISLE Research on three more May 2026 CVEs

FreeBSD's May 20 advisory batch credits Joshua Rogers of AISLE Research on stack and heap overflows and a capability-limit bypass.

Bug class
Stack overflow, heap overflow, and capability-sandbox bypass
Affected codebase
FreeBSD libcasper, fusefs, and cap_net
Credited system
AISLE
Disclosed
May 20, 2026
Attribution
Self-reported attribution
Severity
high
Source status: FreeBSD's upstream advisories credit Joshua Rogers of AISLE Research. AISLE's public platform material establishes the autonomous analyzer context, so the AI-system attribution is self-reported.

Summary

The three advisories cover a libcasper stack overflow, a fusefs heap overflow, and a cap_net logic flaw that could bypass capability limits. They were omitted from the earlier Bugflation FreeBSD AISLE cluster, which covered the April batch only.

Attribution

FreeBSD directly credits the AISLE Research reporter. The entry follows the same direct-attribution treatment as the existing April FreeBSD cluster.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.