Vulnerabilities in Linux and FreeBSD that allow root access to the system

Eight vulnerabilities have been fixed in FreeBSD that could allow privilege escalation in the system. The vulnerabilities have been addressed in updates for FreeBSD 15.1-RELEASE-p3, FreeBSD 15.0-RELEASE-p13, and 14.4-RELEASE-p9.

  • CVE-2026-58094 is a race condition in the implementation of the ioctl operation FIOSSHMLPGCNF, used for configuring the size of shared memory pages. The issue arises due to the lack of lock enforcement during the size change verification operation, allowing incorrect parameters to be set through simultaneous requests with different sizes.
  • CVE-2026-58093 involves accessing memory after it has been freed in the implementation of ioctl TIOCSCTTY, used for managing pseudo-terminals. The problem is caused by improper handling of locks.
  • CVE-2026-58095, CVE-2026-58096, CVE-2026-58097 pertain to issues in the implementation of the PPP (Point-to-Point Protocol), caused by incorrect size checks for processed parameters.
  • CVE-2026-58092 is a logic error in the mac_do module, which provides functionality for executing commands as another user. The issue is due to changes in the structure that stores user rights information — the main group ID was moved to a separate structure, but this change was not reflected in the group_is_primary() function, which continued using the old offset.
  • CVE-2026-58091 involves accessing memory after it has been freed in the implementation of ioctl SNDCTL_DSP_SYNCSTART, used for synchronous playback start on multiple sound devices. The vulnerability is caused by improper lock handling and manifests on systems with multiple sound devices.
  • CVE-2026-58090 concerns accessing memory after it has been freed in the implementation of UNIX sockets, which occurs during the processing of SOCK_STREAM messages.
  • CVE-2026-58089 is a logic error in the hwpmc driver, designed for performance monitoring, which prevents the collection of statistics from being disabled after privilege escalation when running suid root processes. This issue allows a regular user to monitor activity in privileged processes.
  • CVE-2026-18798, CVE-2026-54874, CVE-2026-63072, CVE-2026-63073, CVE-2026-63074, CVE-2026-63075, CVE-2026-63076 — vulnerabilities in the OpenSSL library caused by buffer overflow, double free, formatting string issues, and NULL pointer dereferencing. Potentially, some issues may allow for remote code execution.

Several dangerous issues that allow a local user to gain root privileges have also been identified in the Linux kernel:

  • CVE-2026-53361 — memory access after it has been freed in the AF_UNIX socket implementation. An exploit has been published that allows exiting from an isolated container. The exploit has been demonstrated on Ubuntu 24.04, RHEL 10, and Debian 13 with Linux kernels 6.8, 6.12, 6.14, and 6.17. The issue has been fixed in kernel updates 7.1.0, 6.18.38, 6.12.95, and 6.6.144.
  • CVE-2026-72137 — double free in the nat_keepalive module. The issue manifests starting with kernel 6.11 and has been resolved in releases 7.2.0, 6.12.101, 6.18.40, and 7.1.5. A working exploit has been published that allows gaining root access on the system.
  • Vulnerabilities (CVE not assigned) in the eCryptfs filesystem that could potentially lead to kernel-level code execution when processing specially crafted encrypted files.
  • Vulnerability (CVE not assigned) in the ntfs3 module that allows the substitution of an executable file with the suid root bit when mounting a specially crafted filesystem image (an example of exploiting the vulnerability to gain root access during the automount of a USB drive is shown).
  • A total of 1668 vulnerabilities in the Linux kernel have been disclosed in August.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster