Incorrect authorization in FreeBSD - CVE-2026-101303

 

Incorrect authorization in FreeBSD - CVE-2026-101303

Published: September 30, 2026


Vulnerability identifier: #VU152943
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-101303
CWE-ID: CWE-863
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to bypass jail network isolation.

The vulnerability exists due to improper access control in the IPv6 UDP send path for unconnected sockets when sending UDP datagrams to an IPv6 loopback address from a classic non-VNET jail. A local user can send UDP datagrams to services listening on the host's IPv6 loopback address to bypass jail network isolation.

Only classic non-VNET jails with an IPv6 address are affected.


Affected software

FreeBSD

How to mitigate CVE-2026-101303

Install security update from vendor's website.


External References

Related Security Bulletins