Summary
The three FreeBSD advisories cover flaws in credential changes, file handling, and process tracing. OpenAI says Calif used Codex both to find the issues and to validate them with proof-of-concept local privilege-escalation exploits.
CVE-2026-45253 is also present in the GLM-specific FreeBSD cluster because the upstream advisory separately names GLM-assisted research. The global ledger deduplicates the identifier when calculating its unique-CVE total.
Attribution
The AI workflow is directly documented by OpenAI, while FreeBSD supplies the independent accepted-fix and CVE trail.
References
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.