PT-2026-70015 · Freebsd · Freebsd

CVE-2026-49421

·

Published

2026-06-30

·

Updated

2026-09-01

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions FreeBSD kernel (affected versions not specified)
Description The kernel functions implementing unlinkat(2) and funlinkat(2) fail to pass the AT RESOLVE BENEATH flag to the underlying path lookup process. Although the flag is validated, it is silently dropped, meaning path resolution is not restricted as intended. Consequently, a process attempting to confine path resolution using this flag can resolve paths above the starting directory, potentially allowing the deletion of files outside the intended directory tree, which impacts the integrity of protected information.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-11348
CVE-2026-49421

Affected Products

Freebsd