Vulnerabilities in FreeBSD allow privilege escalation and remote code execution.

FreeBSD has fixed 22 vulnerabilities, one of which potentially allows for remote code execution with root privileges, while 13 can be exploited to elevate privileges within the system. The vulnerabilities are addressed in updates FreeBSD 15.1-RELEASE-p1, FreeBSD 15.0-RELEASE-p11, 14.4-RELEASE-p7, and 14.3-RELEASE-p16.

The most dangerous vulnerability (CVE-2026-49420) is caused by a buffer overflow in the libalias library, used in the kernel-level ipfw packet filter and in the user-space background process natd for address translation of sent or received network packets. The overflow occurred in the RTSP (Real Time Streaming Protocol) handler, which overwrote outgoing network packets using a fixed-size buffer without checking whether the result of the packet overwriting would fit into it.

During the processing of specially crafted RTSP traffic at the NAT gateway, a stack overflow may occur, potentially leading to remote code execution at the kernel level or in the natd process running in the system with root privileges.

As workarounds to block the vulnerability, one can block the loading of the alias_smedia.ko kernel module and remove the mention of the libalias_smedia.so handler from the configuration file /etc/libalias.conf. If RTSP protocol is not used, traffic on network ports 554 and 7070 can be blocked in the rules specified before NAT rules are triggered.

Vulnerabilities that allow a non-privileged local user to gain root privileges:

  • CVE-2026-49415 — a race condition in the execve system call, allowing a local user executing files with the SUID root flag to modify the process's address space through procfs or linprocfs during a small time window that occurs after setting a new virtual address space for the process but before updating its owner data.
  • CVE-2026-49422 — a use-after-free access to already freed memory in the tcp_rack.ko kernel module implementing the RACK (Recent ACKnowledgment) TCP packet loss detection algorithm. This vulnerability can be exploited for privilege escalation through manipulation of a local socket.
  • CVE-2026-49419 — counter underflow in the Jail isolation mechanism implementation. Through manipulations with jail environments using jail descriptors via jail_set and jail_get functions, an attacker can reset the link counter and free the memory for a structure still in use by the kernel, potentially allowing them to escalate their privileges.
  • CVE-2026-49429 — buffer overflow in OpenZFS, allowing a local user with 'userused' ZFS permissions to escalate their privileges through manipulations with the ioctl ZFS_IOC_USERSPACE_MANY.
  • CVE-2026-49427, CVE-2026-49428 — vulnerabilities in the implementation of 'largepage' shared memory objects, leading to access to already freed memory in the kernel, which can be exploited to escalate privileges through manipulations with the sendfile function using the SF_NOCACHE flag or with open and fspacectl functions using the O_TRUNC flag.
  • CVE-2026-49421 — incorrect handling of the AT_RESOLVE_BENEATH flag in the unlinkat and funlinkat system calls can be used to delete files outside the base directory in configurations with restricted filesystem access.
  • CVE-2026-49418 — accessing memory after it has been freed in the virtual memory subsystem, occurring during the msync(MS_INVALIDATE) call for device memory mapping. An attacker with access to a device that supports memory mapping can exploit this vulnerability to escalate their privileges.
  • CVE-2026-49416 — integer overflow in the vt console driver, allowing a local user potentially to escalate their privileges by sending ioctl CONS_HISTORY with an overly large size.
  • CVE-2026-49413 — vulnerability in Linuxulator allowing an unprivileged user to inject their shared library via the LD_PRELOAD environment variable into an executable file with the suid flag and execute their code with the privileges of that executable file.
  • CVE-2026-49412 — access to already freed memory in the IPV6_MSFILTER socket option handler, allowing privilege escalation.
  • CVE-2026-45258 — issues with memory mapping (mmap) support implementation in the sound driver, allowing reading and writing data in kernel memory areas through manipulations with the /dev/dsp device, which is by default writable for everyone.
  • CVE-2026-45257 — a vulnerability in the ktls kernel module that allows an attacker to overwrite any readable file in the page cache. By overwriting a suid root file, such as /bin/su, the attacker can gain root rights in the system.

Less critical vulnerabilities:

  • CVE-2026-49430, CVE-2026-49431 — vulnerabilities in OpenZFS that lead to kernel memory corruption and allow the flag "$hasrecvd" to be set without proper authorization.
  • CVE-2026-49426 — incorrect creation of audit records for ptrace calls. This can be exploited by an attacker to bypass intrusion detection systems.
  • CVE-2026-49423 — a remote DoS vulnerability in the KTLS kernel subsystem, exploited by sending specially crafted TLS packets. This issue is only present on systems using KTLS for TLS processing acceleration (kern.ipc.tls.enable=1).
  • CVE-2026-49424 — a leak of 104 bytes from an uninitialized kernel stack in the implementation of the waitid() system call in Linuxulator.
  • CVE-2026-49425 — data leak from an uninitialized kernel stack in the compat32 subsystem.
  • CVE-2026-58081, CVE-2026-58082 — buffer overflows in the iconv library that can be exploited to attack applications that use iconv to convert untrusted external data in HZ, UTF-7, VIQR, ZW, and ISO-2022 encodings.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster