Source status: FreeBSD-SA-26:44.posixshm directly credits Chris Jarrett-Davies of the OpenAI Codex Security Team for both CVEs.
Summary
The two vulnerabilities affect FreeBSD’s POSIX shared-memory implementation and can allow a local unprivileged process to corrupt kernel memory or escalate privileges. They were fixed in the June 30 advisory batch.
Attribution
This is direct upstream attribution. FreeBSD names both the researcher and the OpenAI Codex Security Team in the advisory’s credits.
References
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.