CVE detail
CVE-2026-7270
An operator precedence bug in the kernel results in a scenario where a buffer overflow causes attacker-controlled data to overwrite adjacent execve(2) argument buffers. The bug may be exploitable by an unprivileged user to obtain superuser privileges.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 13.9 · diversity 11.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
3 source links · newest first
- https://news.ycombinator.com/item?id=48077971news.ycombinator.com
No excerpt available.
Exploitnews.ycombinator.comApr 30, 2026, 7:16 AM No excerpt available.
Exploitblog.calif.ioApr 30, 2026, 7:16 AM- https://security.freebsd.org/advisories/FreeBSD-SA-26:13.exec.ascsecurity.freebsd.org
No excerpt available.
Vendor Advisorysecurity.freebsd.orgApr 30, 2026, 7:16 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-0209CVSS 6.9 · Medium
Under certain administrative conditions, FlashArray Purity may apply snapshot retention policies earlier or later than configured.
- CVE-2026-25233CVSS 7.1 · High
PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, logic bug in the roadmap role check allows non-lead maintainers to create, update…
- CVE-2025-24210CVSS 5.5 · Medium
A logic error was addressed with improved error handling. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13…
- CVE-2025-27512CVSS 2.1 · Low
Zincati is an auto-update agent for Fedora CoreOS hosts. Zincati ships a polkit rule which allows the `zincati` system user to use the actions `org.projectatomic.rpmostree1.deploy…
- CVE-2024-49736CVSS 5.5 · Medium
In onClick of MainClear.java, there is a possible way to trigger factory reset without explicit user consent due to a logic error in the code. This could lead to local denial of s…
- CVE-2017-13322CVSS 10.0 · Critical
In endCallForSubscriber of PhoneInterfaceManager.java, there is a possible way to prevent access to emergency services due to a logic error in the code. This could lead to a local…