Path Resolution Vulnerability in FreeBSD Kernel Functions
CVE-2026-49421

Currently unrated

Key Information:

Vendor

FreeBSD

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-49421?

A vulnerability in the FreeBSD kernel affects the unlinkat(2) and funlinkat(2) functions. This vulnerability stems from inadequate validation of the AT_RESOLVE_BENEATH flag during path lookup procedures. As a result, the function can unintentionally allow processes to resolve paths beyond their designated directories, leading to the potential deletion of files outside of the expected directory tree. This flaw undermines the intended restrictions in place for path resolution, posing risks to system integrity and data security.

Affected Version(s)

FreeBSD 15.1-RELEASE

FreeBSD 15.0-RELEASE

FreeBSD 14.4-RELEASE

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yuxiang Yang, Yizhou Zhao, Ao Wang, Xuewei Feng, Qi Li, and Ke Xu from Tsinghua University using GLM-5.1 from Z.ai
.