PT-2026-78318 · Freebsd · Freebsd
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
The product name cannot be determined (affected versions not specified)
Description
A logic error occurs where
PRIV KTRACE is consistently denied to a root user within a jail. Consequently, tracing configured by a jailed root user is not flagged as privileged. This allows an unprivileged user in the same jail, provided they have permission to debug the target process, to modify the jailed root user's ktrace(2) flags or disable tracing entirely, preventing the jailed root user from reliably tracing unprivileged processes.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Freebsd