PT-2026-81936 · Freebsd · Freebsd
CVSS v3.1
7.0
High
| Vector | AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
The product name cannot be determined (affected versions not specified)
Description
A race condition exists in the TIOCSCTTY ioctl handler. The handler releases the tty lock to acquire the process tree lock but fails to revalidate the terminal state after reacquiring the tty lock. This allows a terminal being concurrently destroyed to be linked to the calling process session, enabling an unprivileged local user to escalate privileges.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Race Condition
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Freebsd