Improper privilege management in FreeBSD - CVE-2026-49413
Published: June 11, 2026
FreeBSD
Detailed vulnerability description
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to improper privilege management in the Linuxulator execution of set-user-ID and set-group-ID Linux binaries when constructing the ELF auxiliary vector during execve(2). A local user can inject a shared library via LD_PRELOAD to escalate privileges.
Only systems with the Linux compatibility module loaded and Linux set-user-ID or set-group-ID executables present are vulnerable.