All findings

openai-daybreak-openbsd-semaphore-uaf high

OpenAI Daybreak finds and patches 23-year-old OpenBSD semaphore UAF

OpenAI reports that its models found a 23-year-old use-after-free in OpenBSD System V semaphores that could permit local root escalation; OpenBSD accepted the patch.

Bug class
Use-after-free and local privilege escalation
Affected codebase
OpenBSD kernel
Credited system
OpenAI Daybreak
Disclosed
June 22, 2026
Attribution
Direct source attribution
Severity
high
Introduced
January 1, 2003 (23 years before disclosure)
Source status: OpenAI's primary Daybreak disclosure describes discovery, reproduction, and root-escalation impact; the linked OpenBSD source commit provides the public accepted-fix record. No CVE was public at indexing time.

Summary

The bug was a use-after-free in OpenBSD’s implementation of System V semaphores. OpenAI says its researchers reproduced the issue and confirmed that an unprivileged local user could use it to escalate to root. OpenBSD accepted a source fix before the Daybreak disclosure.

This is indexed without a CVE because Bugflation’s methodology permits a specific, accepted, publicly patched security issue when the upstream evidence is sufficient.

Attribution

The AI-discovery attribution comes directly from OpenAI’s Daybreak team. The OpenBSD commit independently confirms acceptance and remediation.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.