All findings

CVE-2026-45253 + 7 more high

FreeBSD advisories directly credit Z.AI GLM across eight CVEs

FreeBSD credits Z.AI GLM-assisted research on eight vulnerabilities spanning ptrace, threads, jails, unlinkat, kernel TLS, and ZFS.

Bug class
Privilege escalation, use-after-free, state leakage, and filesystem boundary failures
Affected codebase
FreeBSD kernel, libc, and ZFS
Credited system
Z.AI GLM
Disclosed
June 30, 2026
Attribution
Direct source attribution
Severity
high
Source status: FreeBSD's own advisories name GLM or the GLM-5.1 security team. Several reports have additional independent finders, which the entry preserves as shared credit.

Summary

The public FreeBSD record now contains eight CVEs tied to GLM-assisted research. The affected paths include process tracing, thread state, jail isolation, pathname operations, kernel TLS, and three ZFS defects.

The ZFS advisory covers three CVEs and credits both the GLM-5.1 security team and Quarkslab. CVE-2026-45253 was also independently found by Calif using OpenAI Codex. Those overlaps are part of the record, not duplicates to erase.

Attribution

FreeBSD is the attribution source, making this a direct-credit cluster. The entry records GLM participation while avoiding claims of exclusive discovery where the advisories list other researchers.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.