FreeBSD has addressed 4 vulnerabilities that allow privilege escalation, along with one remote root vulnerability.

FreeBSD has fixed 7 vulnerabilities, one of which allows remote code execution with root privileges, while four allow privilege escalation in the system. These vulnerabilities have been resolved in FreeBSD updates 15.0-RELEASE-p9, 14.4-RELEASE-p5, and 14.3-RELEASE-p14.

  • CVE-2026-45255 - The bsdinstall installer and the bsdconfig configurator lacked proper escaping of special characters in a shell script that displays a list of available wireless networks found during scanning to the user. An attacker can create a rogue access point and assign a specially crafted network identifier (SSID) containing executable shell constructs (e.g., "test`id`"). When the user invokes the function to search for wireless networks, the injected shell commands will be executed on the user’s system with root privileges (choice or connection to the attacker’s network is not required, simply initiating the scanning of networks is sufficient).
  • CVE-2026-45250 - Stack overflow in the setcred system call, allowing a local unprivileged user to execute their code at the kernel level. The issue arises due to incorrect size verification of the data being placed in the buffer — "sizeof(gid_t)" was replaced with "sizeof(*groups)". Elevated privileges are required to access the setcred system call, but the vulnerability exists in the initial copying code into a separate buffer of the user-provided group list, executed before privilege verification.
  • CVE-2026-45251 - Use-after-free memory access in the select and poll system calls, occurring if a provided file descriptor is closed before unlocking a thread that waits for file descriptors from the select and poll system calls. Successful exploitation allows an unprivileged user to execute code at the kernel level.
  • CVE-2026-45253 - Lack of adequate validation of parameters passed to the ptrace system call when performing the PT_SC_REMOTE operation. This vulnerability allows an unprivileged user to facilitate the execution of arbitrary code in the kernel, even if the target debugged process does not have special privileges.
  • CVE-2026-39461 — stack overflow in the libcasper library, which provides applications isolated by the Capsicum mechanism access to system interfaces. When interacting with the handler through UNIX sockets, the library uses the select system call to wait for incoming data but does not check if the socket descriptor complies with the select limit FD_SETSIZE (1024). An attacker can initiate the allocation of large file descriptors in a libcasper-based application, causing a stack overflow. Such manipulations with setuid root programs can achieve code execution with root privileges.
  • CVE-2026-45254 — the possibility of bypassing cap_net limits in the application because a missing key is treated as "allow any" instead of being blocked.
  • CVE-2026-45252 — buffer overflow in the fusefs module when processing FUSE_LISTXATTR messages, allowing reading up to 253 bytes from the kernel memory outside the buffer or writing up to 250 bytes into an unused area of the heap.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster