PT-2026-71932 · Freebsd · Freebsd Kernel+1
CVSS v3.1
3.3
Low
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
FreeBSD kernel (affected versions not specified)
Description
When auditing a system call executed via
ptrace(PT SC REMOTE), the kernel passes the return value of an internal setup function to AUDIT SYSCALL EXIT() instead of the actual result of the executed system call. This causes audit records for system calls that returned an error to incorrectly indicate that the operation succeeded. An attacker with debugging privileges could exploit this behavior to create misleading audit trails, which may undermine audit-based Intrusion Detection Systems (IDS).Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Freebsd Kernel
Freebsd