PT-2026-53061 · Freebsd Foundation+1 · Freebsd
CVSS v3.1
6.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
FreeBSD (affected versions not specified)
Description
The implementation of the
kern sigqueue() function failed to include a capability mode check. This allows a process operating in Capsicum capability mode—a security framework that restricts process privileges—to use the sigqueue(2) system call to send signals to any process it would normally be able to signal under standard Unix permissions. Consequently, a compromised sandboxed process can bypass sandbox restrictions to interfere with other processes, such as by sending SIGKILL or SIGSTOP signals. This impact extends to any process running under the same user or any process on the system if the sandboxed process has superuser privileges.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Incorrect Privilege Assignment
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Freebsd