NullFS Mount Escape Vulnerability in FreeBSD Jail Environment
CVE-2025-15547
8.8HIGH
What is CVE-2025-15547?
In FreeBSD's jail environment, a configuration flaw allows privileged users to utilize the nullfs(4) mount option to escape the chroot confines of the jail. When nullfs mounts are permitted within a jail, this vulnerability arises due to the kernel's path lookup logic, which can be manipulated by a jailed root user. Consequently, this can lead to unauthorized access to the complete filesystem of the host or parent jail, posing significant risks to system integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
FreeBSD 14.3-RELEASE
FreeBSD 13.5-RELEASE
