Privilege Escalation Vulnerability in FreeBSD's KTrace for Jailed Users
CVE-2026-58086

Currently unrated

Key Information:

Vendor

FreeBSD

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-58086?

A configuration oversight in FreeBSD's KTrace functionality has resulted in an inadvertent privilege escalation risk for jailed root users. Due to an unrelated code alteration, the PRIV_KTRACE privilege was erroneously denied to jailed root users. Consequently, this change undermines the ability of these users to trace their processes adequately, as unprivileged users within the jail can manipulate KTrace settings or disable tracing altogether. This vulnerability can lead to significant security risks if not addressed, allowing potential exposure of sensitive operational details.

Affected Version(s)

FreeBSD 15.1-RELEASE

FreeBSD 15.0-RELEASE

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alexander Leidinger
.