All findings

CVE-2026-49427, CVE-2026-49428 high

FreeBSD credits OpenAI Codex Security on two POSIX shared-memory CVEs

FreeBSD directly credits the OpenAI Codex Security Team for two POSIX shared-memory flaws with local kernel privilege-escalation impact.

Bug class
Kernel memory corruption and local privilege escalation
Affected codebase
FreeBSD POSIX shared memory
Credited system
OpenAI Aardvark / Codex Security
Disclosed
June 30, 2026
Attribution
Direct source attribution
Severity
high
Source status: FreeBSD-SA-26:44.posixshm directly credits Chris Jarrett-Davies of the OpenAI Codex Security Team for both CVEs.

Summary

The two vulnerabilities affect FreeBSD’s POSIX shared-memory implementation and can allow a local unprivileged process to corrupt kernel memory or escalate privileges. They were fixed in the June 30 advisory batch.

Attribution

This is direct upstream attribution. FreeBSD names both the researcher and the OpenAI Codex Security Team in the advisory’s credits.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.