Problem Description:
Three flaws allow a jailed process to bypass FD_RESOLVE_BENEATH:
- When fdescfs(4) was mounted in a jail with the "nodup" option,
opening /dev/fd/N returned a descriptor that did not inherit
FD_RESOLVE_BENEATH or the Capsicum capability rights of descriptor
N. (CVE-2026-101304)
- renameat(2) did not enforce FD_RESOLVE_BENEATH on its directory
arguments. A jailed process could rename a directory relative to
a restricted descriptor, then escape the jail root via fchdir(2).
This requires the directory to reside on a filesystem that is also
reachable from the jail's root. (CVE-2026-101305)
- SCM_RIGHTS file descriptor passing did not preserve FD_RESOLVE_BENEATH
when a descriptor was transferred. A process could clear the
restriction by sending the descriptor to itself over a Unix domain
socket. (CVE-2026-101306)
Impact:
A process in a jail that has received a directory file descriptor
from another jail can use these techniques to escape the jail's
filesystem root restriction.