New FreeBSD Vulnerabilities Allow Jail Escapes and Kernel Panics
ID: e4c2bc90-0259-5aaa-b2a5-507da22a03f2
STIX ID: report--e4c2bc90-0259-5aaa-b2a5-507da22a03f2
Feed Name: securityonline.info
FreeBSD published advisories for two serious vulnerabilities: CVE-2025-15576 allows jailed processes to obtain directory descriptors that bypass jail roots (nullfs + Unix domain socket FD passing), effectively enabling jailed processes to break out and access the full filesystem; CVE-2026-3038 is a routing-socket stack buffer overflow that can cause a kernel panic (local DoS) and — if canary values can be discovered via other bugs — could enable local privilege escalation. FreeBSD recommends immediate patching and administrators should prevent unprivileged users from passing directory descriptors to jailed processes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
