Summary
On April 21, 2026, FreeBSD published two additional kernel security advisories credited to “Nicholas Carlini using Claude, Anthropic.”
- CVE-2026-5398 covers a TIOCNOTTY use-after-free where a malicious process can abuse a dangling pointer to grant itself root privileges.
- CVE-2026-6386 covers missing large-page handling in pmap_pkru_update_range(), allowing an unprivileged user on affected amd64 systems to cause memory to be overwritten outside intended permissions.
Why this matters
CVE-2026-4747 is the headline FreeBSD case because Anthropic says Mythos Preview fully autonomously discovered and exploited it. These follow-up advisories matter for a different reason: the FreeBSD project’s own advisory stream now contains multiple direct “using Claude” credits in core kernel components.
Caveat
The public FreeBSD advisories do not name the exact Claude model or claim full autonomy. This entry therefore uses the generic Claude / Anthropic Research system profile rather than assigning the follow-ups to Mythos Preview.
References
- FreeBSD-SA-26:10.tty advisory
- FreeBSD-SA-26:11.amd64 advisory
- CVE record: CVE-2026-5398
- CVE record: CVE-2026-6386
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.