PT-2026-78318 · Freebsd · Freebsd

·

CVE-2026-58086

·

Published

2026-08-19

·

Updated

2026-08-19

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions The product name cannot be determined (affected versions not specified)
Description A logic error occurs where PRIV KTRACE is consistently denied to a root user within a jail. Consequently, tracing configured by a jailed root user is not flagged as privileged. This allows an unprivileged user in the same jail, provided they have permission to debug the target process, to modify the jailed root user's ktrace(2) flags or disable tracing entirely, preventing the jailed root user from reliably tracing unprivileged processes.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-58086

Affected Products

Freebsd