Privilege Escalation Vulnerability in FreeBSD's hwpmc Component
CVE-2026-58089

Currently unrated

Key Information:

Vendor

FreeBSD

Status
Vendor
CVE Published:
26 August 2026

What is CVE-2026-58089?

The hwpmc component in FreeBSD mishandles process management when a setuid or setgid binary is executed. An unprivileged local user with attached Performance Monitoring Counters (PMCs) can bypass intended protections, continuing to monitor processes after their execution. This flaw arises from an inverted check that overlooks the privileges of the user, potentially leading to unauthorized information access and manipulation during critical operations.

Affected Version(s)

FreeBSD 15.1-RELEASE

FreeBSD 15.0-RELEASE

FreeBSD 14.4-RELEASE

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alexander Leidinger
.