FreeBSD
cpe:2.3:o:freebsd:freebsd:*:*:*:*:*:*:*
- <= 15.0-RELEASE
- <= 14.4-RELEASE
- <= 14.3-RELEASE
A vulnerability exists in the ptrace system call, specifically with the PT_SC_REMOTE operation, across all supported FreeBSD versions. The issue arises because the ptrace call failed to properly validate parameters for certain meta-system calls, allowing unprivileged local users to execute arbitrary code in the kernel. This could lead to unauthorized privilege escalation and potentially full control over the affected system.
Exploitation of this vulnerability allows an unprivileged local user to escalate privileges, with the potential to gain full control of the affected system.
Users can upgrade to a supported FreeBSD stable or release branch dated after the correction date and reboot the system. Instructions for updating via the pkg utility, freebsd-update utility, or by applying a source code patch are available in the FreeBSD Security Advisory FreeBSD-SA-26:21.ptrace.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.