Privilege Escalation Vulnerability in FreeBSD's KTrace for Jailed Users
CVE-2026-58086
Currently unrated
What is CVE-2026-58086?
A configuration oversight in FreeBSD's KTrace functionality has resulted in an inadvertent privilege escalation risk for jailed root users. Due to an unrelated code alteration, the PRIV_KTRACE privilege was erroneously denied to jailed root users. Consequently, this change undermines the ability of these users to trace their processes adequately, as unprivileged users within the jail can manipulate KTrace settings or disable tracing altogether. This vulnerability can lead to significant security risks if not addressed, allowing potential exposure of sensitive operational details.
Affected Version(s)
FreeBSD 15.1-RELEASE
FreeBSD 15.0-RELEASE
