FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

FreeBSD -- Multiple jail filesystem root escapes

Affected packages
15.1 <= FreeBSD-kernel < 15.1_4
15.0 <= FreeBSD-kernel < 15.0_14
14.5 <= FreeBSD-kernel < 14.5_1
14.4 <= FreeBSD-kernel < 14.4_10

Details

VuXML ID 1fe3495b-bccd-11f1-906f-bc241121aa0a
Discovery 2026-09-29
Entry 2026-09-30

Problem Description:

Three flaws allow a jailed process to bypass FD_RESOLVE_BENEATH:

  1. When fdescfs(4) was mounted in a jail with the "nodup" option, opening /dev/fd/N returned a descriptor that did not inherit FD_RESOLVE_BENEATH or the Capsicum capability rights of descriptor N. (CVE-2026-101304)
  2. renameat(2) did not enforce FD_RESOLVE_BENEATH on its directory arguments. A jailed process could rename a directory relative to a restricted descriptor, then escape the jail root via fchdir(2). This requires the directory to reside on a filesystem that is also reachable from the jail's root. (CVE-2026-101305)
  3. SCM_RIGHTS file descriptor passing did not preserve FD_RESOLVE_BENEATH when a descriptor was transferred. A process could clear the restriction by sending the descriptor to itself over a Unix domain socket. (CVE-2026-101306)

Impact:

A process in a jail that has received a directory file descriptor from another jail can use these techniques to escape the jail's filesystem root restriction.

References

CVE Name CVE-2026-101304
CVE Name CVE-2026-101305
CVE Name CVE-2026-101306
FreeBSD Advisory SA-26:66.jail