Privilege Escalation Vulnerability in FreeBSD Terminal Handling
CVE-2026-58093
Currently unrated
What is CVE-2026-58093?
A vulnerability exists within the TIOCSCTTY ioctl handler in FreeBSD that allows an unprivileged local user to exploit a race condition. The handler improperly manages the tty lock while trying to acquire the process tree lock. This flaw enables the potential re-linking of a terminal, which is being destroyed, to the user's process session. This can lead to unauthorized privilege escalation, posing a significant risk to system security.
Affected Version(s)
FreeBSD 15.1-RELEASE
FreeBSD 15.0-RELEASE
FreeBSD 14.4-RELEASE
