Privilege Escalation Vulnerability in FreeBSD TCP Stack
CVE-2026-49422
Currently unrated
What is CVE-2026-49422?
A flaw in the FreeBSD TCP stack arises from the RACK setsockopt(2) handler improperly managing the connection lock during the copying of option data from userspace. This mismanagement may allow a local user to exploit a timing window where the pointer to the TCP stack's per-connection control block becomes invalid after switching stacks. As a result, an unprivileged local user could potentially escalate their privileges, posing a significant security risk.
Affected Version(s)
FreeBSD 15.1-RELEASE
FreeBSD 15.0-RELEASE
FreeBSD 14.4-RELEASE
