{"id":182528,"date":"2026-07-08T04:53:20","date_gmt":"2026-07-08T02:53:20","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimosti-vo-freebsd-dopuskayushhie-povyshenie-privilegij-i-udalyonnoe-vypolnenie-koda"},"modified":"2026-07-08T04:53:20","modified_gmt":"2026-07-08T02:53:20","slug":"uyazvimosti-vo-freebsd-dopuskayushhie-povyshenie-privilegij-i-udalyonnoe-vypolnenie-koda","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimosti-vo-freebsd-dopuskayushhie-povyshenie-privilegij-i-udalyonnoe-vypolnenie-koda","title":{"rendered":"Vulnerabilities in FreeBSD allow privilege escalation and remote code execution.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>FreeBSD has fixed 22 vulnerabilities, one of which potentially allows for remote code execution with root privileges, while 13 can be exploited to elevate privileges within the system. The vulnerabilities are addressed in updates FreeBSD 15.1-RELEASE-p1, FreeBSD 15.0-RELEASE-p11, 14.4-RELEASE-p7, and 14.3-RELEASE-p16.     <\/p>\n<p>The most dangerous vulnerability (CVE-2026-49420) is caused by a buffer overflow in the libalias library, used in the kernel-level ipfw packet filter and in the user-space background process natd for address translation of sent or received network packets. The overflow occurred in the RTSP (Real Time Streaming Protocol) handler, which overwrote outgoing network packets using a fixed-size buffer without checking whether the result of the packet overwriting would fit into it.    <\/p>\n<p>During the processing of specially crafted RTSP traffic at the NAT gateway, a stack overflow may occur, potentially leading to remote code execution at the kernel level or in the natd process running in the system with root privileges.     <\/p>\n<p>As workarounds to block the vulnerability, one can block the loading of the alias_smedia.ko kernel module and remove the mention of the libalias_smedia.so handler from the configuration file \/etc\/libalias.conf. If RTSP protocol is not used, traffic on network ports 554 and 7070 can be blocked in the rules specified before NAT rules are triggered.    <\/p>\n<p>Vulnerabilities that allow a non-privileged local user to gain root privileges:  <\/p>\n<ul>\n<li class=\"l\">  CVE-2026-49415 \u2014 a race condition in the execve system call that allows a local user executing SUID root binaries to modify the process's address space through procfs or linprocfs in a small time window occurring after setting up a new process virtual address space but before updating its ownership data.\n<li class=\"l\"> CVE-2026-49422 \u2014 use-after-free memory access in the tcp_rack.ko kernel module, which implements the RACK (Recent ACKnowledgment) TCP packet loss detection algorithm. This vulnerability can be exploited for privilege escalation through manipulation of a local socket.\n<li class=\"l\"> CVE-2026-49419 \u2014 underflow in the reference count management mechanism of the Jail isolation. By manipulating jail environments using jail descriptors with the jail_set and jail_get functions, an attacker could reset the reference count and free memory for a structure still in use by the kernel, potentially exploitable for privilege escalation.\n<li class=\"l\"> CVE-2026-49429 \u2014 buffer overflow in OpenZFS, allowing a local user with ZFS 'userused' rights to escalate privileges through manipulation of ioctl ZFS_IOC_USERSPACE_MANY.\n<li class=\"l\"> CVE-2026-49427, CVE-2026-49428 \u2014 vulnerabilities in the implementation of 'largepage' shared memory objects that lead to use-after-free memory access in the kernel, which can be exploited for privilege escalation through manipulation of the sendfile function with the SF_NOCACHE flag or the open and fspacectl functions with the O_TRUNC flag.\n<li class=\"l\"> CVE-2026-49421 \u2014 improper handling of the AT_RESOLVE_BENEATH flag in the unlinkat and funlinkat system calls may be used to delete files outside the base directory in configurations with restricted file system access.\n<li class=\"l\"> CVE-2026-49418 \u2014 accessing memory after it has been freed in the virtual memory subsystem, occurring during a call to the msync(MS_INVALIDATE) function for device memory mapping. An attacker with access to a device supporting memory mapping may exploit this vulnerability for privilege escalation.\n<li class=\"l\"> CVE-2026-49416 \u2014 integer overflow in the vt console driver, allowing a local user potentially to escalate privileges by sending an ioctl CONS_HISTORY with an excessively large size.\n<li class=\"l\"> CVE-2026-49413 \u2014 a vulnerability in Linuxulator that allows an unprivileged user to substitute their shared library via the LD_PRELOAD environment variable in an executable file with the suid flag and execute their code with the privileges of that executable.\n<li class=\"l\"> CVE-2026-49412 \u2014 accessing already freed memory in the IPV6_MSFILTER option handler in sockets, allowing privilege escalation.\n<li class=\"l\"> CVE-2026-45258 \u2014 issues with the implementation of memory mapping (mmap) support in the sound driver, allowing data to be read and written in kernel memory regions through manipulations with the \/dev\/dsp device, which is by default writable by everyone.\n<li class=\"l\"> CVE-2026-45257 \u2014 a vulnerability in the ktls kernel module that allows overwriting any file accessible for reading in the page cache by an attacker. By overwriting a suid root file like \/bin\/su, the attacker can gain root privileges on the system.              <\/ul>\n<p>Less critical vulnerabilities:  <\/p>\n<ul>\n<li class=\"l\"> CVE-2026-49430, CVE-2026-49431 \u2014 vulnerabilities in OpenZFS that lead to kernel memory corruption and the ability to set the $hasrecvd flag without the necessary permissions.\n<li class=\"l\"> CVE-2026-49426 \u2014 incorrect creation of audit records for ptrace calls. Can be exploited by an attacker to bypass intrusion detection systems.\n<li class=\"l\"> CVE-2026-49423 \u2014 a remote DoS vulnerability in the KTLS kernel subsystem, exploited by sending specially crafted TLS packets. The issue occurs only on systems using KTLS for accelerated TLS processing (kern.ipc.tls.enable=1).\n<li class=\"l\"> CVE-2026-49424 \u2014 a leak of 104 bytes from an uninitialized kernel stack in the implementation of the waitid() system call in Linuxulator.\n<li class=\"l\"> CVE-2026-49425 \u2014 data leak from an uninitialized kernel stack in the compat32 subsystem.\n<li class=\"l\"> CVE-2026-58081, CVE-2026-58082 \u2014 buffer overflows in the iconv library that can be used to attack applications using iconv to convert untrusted external data in the HZ, UTF-7, VIQR, ZW, and ISO-2022 encodings.      <\/ul>\n<p>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=65860\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412\u043e FreeBSD \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u043e 22 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438, \u0438\u0437 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043e\u0434\u043d\u0430 \u043f\u043e\u0442\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 root, \u0430 13 \u0434\u0430\u044e\u0442 \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u044c \u043f\u043e\u0432\u044b\u0441\u0438\u0442\u044c \u0441\u0432\u043e\u0438 \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0438 \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u044b \u0432 \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u044f\u0445 FreeBSD 15.1-RELEASE-p1, FreeBSD 15.0-RELEASE-p11, 14.4-RELEASE-p7 \u0438 14.3-RELEASE-p16. \u041d\u0430\u0438\u0431\u043e\u043b\u0435\u0435 \u043e\u043f\u0430\u0441\u043d\u0430\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2026-49420) \u0432\u044b\u0437\u0432\u0430\u043d\u0430 \u043f\u0435\u0440\u0435\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435\u043c \u0431\u0443\u0444\u0435\u0440\u0430 \u0432 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0435 libalias, \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u043e\u0439 \u0432 \u0440\u0430\u0431\u043e\u0442\u0430\u044e\u0449\u0435\u043c \u043d\u0430 \u0443\u0440\u043e\u0432\u043d\u0435 \u044f\u0434\u0440\u0430 \u043f\u0430\u043a\u0435\u0442\u043d\u043e\u043c \u0444\u0438\u043b\u044c\u0442\u0440\u0435 ipfw [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":10,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-182528","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412\u043e FreeBSD \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u043e 22 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438, \u0438\u0437 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043e\u0434\u043d\u0430 \u043f\u043e\u0442\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 root, \u0430 13 \u0434\u0430\u044e\u0442 \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u044c \u043f\u043e\u0432\u044b\u0441\u0438\u0442\u044c \u0441\u0432\u043e\u0438 \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0438 \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Alexander Kovalev\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimosti-vo-freebsd-dopuskayushhie-povyshenie-privilegij-i-udalyonnoe-vypolnenie-koda\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432\u043e FreeBSD, \u0434\u043e\u043f\u0443\u0441\u043a\u0430\u044e\u0449\u0438\u0435 \u043f\u043e\u0432\u044b\u0448\u0435\u043d\u0438\u0435 \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0439 \u0438 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e\u0435 \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435 \u043a\u043e\u0434\u0430 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412\u043e FreeBSD \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u043e 22 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438, \u0438\u0437 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043e\u0434\u043d\u0430 \u043f\u043e\u0442\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 root, \u0430 13 \u0434\u0430\u044e\u0442 \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u044c \u043f\u043e\u0432\u044b\u0441\u0438\u0442\u044c \u0441\u0432\u043e\u0438 \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0438 \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimosti-vo-freebsd-dopuskayushhie-povyshenie-privilegij-i-udalyonnoe-vypolnenie-koda\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-07-08T02:53:20+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-07-08T02:53:20+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerabilities in FreeBSD allowing privilege escalation and remote code execution | ProHoster","description":"In FreeBSD, 22 vulnerabilities have been fixed, one of which may allow remote code execution with root privileges, and 13 provide the ability to escalate privileges in the system.","canonical_url":"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimosti-vo-freebsd-dopuskayushhie-povyshenie-privilegij-i-udalyonnoe-vypolnenie-koda","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432\u043e FreeBSD, \u0434\u043e\u043f\u0443\u0441\u043a\u0430\u044e\u0449\u0438\u0435 \u043f\u043e\u0432\u044b\u0448\u0435\u043d\u0438\u0435 \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0439 \u0438 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e\u0435 \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435 \u043a\u043e\u0434\u0430 | ProHoster","og:description":"\u0412\u043e FreeBSD \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u043e 22 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438, \u0438\u0437 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043e\u0434\u043d\u0430 \u043f\u043e\u0442\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 root, \u0430 13 \u0434\u0430\u044e\u0442 \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u044c \u043f\u043e\u0432\u044b\u0441\u0438\u0442\u044c \u0441\u0432\u043e\u0438 \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0438 \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435.","og:url":"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimosti-vo-freebsd-dopuskayushhie-povyshenie-privilegij-i-udalyonnoe-vypolnenie-koda","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2026-07-08T02:53:20+00:00","article:modified_time":"2026-07-08T02:53:20+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"182528","title":null,"description":null,"keywords":null,"keyphrases":{"focus":[],"additional":[]},"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2026-08-05 12:22:08","updated":"2026-08-05 12:22:08","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/182528","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=182528"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/182528\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=182528"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=182528"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=182528"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}