PT-2026-70014 · Freebsd · Freebsd
CVE-2026-49419
·
Published
2026-06-30
·
Updated
2026-09-01
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FreeBSD (affected versions not specified)
Description
An issue exists in the
kern jail set() and kern jail get() functions when the JAIL AT DESC flag is used. The system releases the reference to the caller's current prison before searching for the jail descriptor; if the lookup fails, the error-handling process releases the same reference again. This double-free condition allows an unprivileged local user to trigger a prison reference count underflow, potentially causing the prison structure to be freed while still active. On a jail host, this typically leads to a system panic, but users operating within a jail may be able to leverage this to elevate privileges.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Double Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Freebsd