SB2026093081 - Multiple vulnerabilities in FreeBSD



SB2026093081 - Multiple vulnerabilities in FreeBSD

Published: September 30, 2026 Updated: September 30, 2026

Security Bulletin ID SB2026093081
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 8
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 13% Low 88%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 8 vulnerabilities.


1) Buffer overflow (CVE-ID: CVE-2026-58098)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 7.2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to escalate privileges.

The vulnerability exists due to improper validation of a semaphore set identifier in semop(2) when waking after waiting for a semaphore condition. A local user can create and destroy semaphore sets in the same table slot while a semop(2) call is blocked to escalate privileges.


2) Out-of-bounds read (CVE-ID: CVE-2026-58100)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to escalate privileges.

The vulnerability exists due to an out-of-bounds read in kqueue_fork_copy_knote() when transferring knotes to a child process during fork. A local user can concurrently grow the parent's file descriptor table and register knotes with file descriptor numbers beyond the child table's bounds to escalate privileges.


3) Use-after-free (CVE-ID: CVE-2026-58099)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to escalate privileges.

The vulnerability exists due to use-after-free in the kqueue copy-on-fork implementation when copying knotes to a child process during fork. A local user can trigger a race involving marker knotes to escalate privileges.


4) Improper access control (CVE-ID: CVE-2026-101306)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to escape the jail's filesystem root restriction.

The vulnerability exists due to improper access control in SCM_RIGHTS file descriptor passing when transferring a descriptor over a Unix domain socket. A local user can send a restricted descriptor to itself over a Unix domain socket to escape the jail's filesystem root restriction.

Exploitation requires a directory file descriptor received from another jail.


5) Improper access control (CVE-ID: CVE-2026-101305)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to escape the jail's filesystem root restriction.

The vulnerability exists due to improper access control in renameat(2) when renaming a directory relative to a restricted descriptor. A local user can rename a directory and use fchdir(2) to escape the jail's filesystem root restriction.

Exploitation requires a directory file descriptor received from another jail, and the directory must reside on a filesystem reachable from the jail's root.


6) Improper access control (CVE-ID: CVE-2026-101304)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to escape the jail's filesystem root restriction.

The vulnerability exists due to improper access control in fdescfs(4) when opening /dev/fd/N with fdescfs mounted using the nodup option. A local user can open /dev/fd/N to escape the jail's filesystem root restriction.

Exploitation requires a directory file descriptor received from another jail.


7) Off-by-one (CVE-ID: CVE-2026-101302)

CWE-ID: CWE-193 - Off-by-one Error

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to an off-by-one error in the receive-side kernel TLS record-type search when processing a specially crafted TLS 1.3 record. A remote attacker can send a specially crafted TLS 1.3 record to cause a denial of service.

Exploitation requires an application to enable receive-side software KTLS.


8) Incorrect authorization (CVE-ID: CVE-2026-101303)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to bypass jail network isolation.

The vulnerability exists due to improper access control in the IPv6 UDP send path for unconnected sockets when sending UDP datagrams to an IPv6 loopback address from a classic non-VNET jail. A local user can send UDP datagrams to services listening on the host's IPv6 loopback address to bypass jail network isolation.

Only classic non-VNET jails with an IPv6 address are affected.


Remediation

Install update from vendor's website.