Privilege Escalation Vulnerability in FreeBSD Terminal Handling
CVE-2026-58093

Currently unrated

Key Information:

Vendor

FreeBSD

Status
Vendor
CVE Published:
26 August 2026

What is CVE-2026-58093?

A vulnerability exists within the TIOCSCTTY ioctl handler in FreeBSD that allows an unprivileged local user to exploit a race condition. The handler improperly manages the tty lock while trying to acquire the process tree lock. This flaw enables the potential re-linking of a terminal, which is being destroyed, to the user's process session. This can lead to unauthorized privilege escalation, posing a significant risk to system security.

Affected Version(s)

FreeBSD 15.1-RELEASE

FreeBSD 15.0-RELEASE

FreeBSD 14.4-RELEASE

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

tsune of GMO Cybersecurity by Ierae, Inc. working with TrendAI Zero Day Initiative
.