FreeBSD
cpe:2.3:o:freebsd:freebsd:*:*:*:*:*:*:*
- >= 15.0-RELEASE, < 15.0-RELEASE-p9
- >= 14.4-RELEASE, < 14.4-RELEASE-p5
- >= 14.3-RELEASE, < 14.3-RELEASE-p14
A vulnerability exists in the FreeBSD libcap_net service, which is used by Capsicum-sandboxed applications to manage networking capabilities. When an application requests a new set of permissions, any keys omitted from the new limit are incorrectly interpreted as 'allow any', rather than being rejected. This flaw can enable an application to extend its previously restricted network operations, potentially leading to unauthorized access or actions.
Exploitation of this vulnerability could allow applications to gain extended network permissions, bypassing previous restrictions and potentially leading to unauthorized network operations.
Users can upgrade to a supported FreeBSD stable or release branch dated after the correction date. Instructions for updating via the pkg utility, freebsd-update utility, or by applying a source code patch are available in the FreeBSD Security Advisory FreeBSD-SA-26:24.cap_net.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.