Summary
The bug was a use-after-free in OpenBSD’s implementation of System V semaphores. OpenAI says its researchers reproduced the issue and confirmed that an unprivileged local user could use it to escalate to root. OpenBSD accepted a source fix before the Daybreak disclosure.
This is indexed without a CVE because Bugflation’s methodology permits a specific, accepted, publicly patched security issue when the upstream evidence is sufficient.
Attribution
The AI-discovery attribution comes directly from OpenAI’s Daybreak team. The OpenBSD commit independently confirms acceptance and remediation.
References
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.