CVE-2026-58086
Description
AI Translation Available
As an inadvertent side effect of an unrelated code change, PRIV_KTRACE was always denied to a jailed root user. Tracing configured by a jailed root user was therefore not flagged as privileged.
An unprivileged user in a jail that has permission to debug the target process can modify the jailed root user's ktrace(2) flags, or disable tracing outright. A jailed root user therefore cannot reliably trace unprivileged processes.
EPSS (Exploit Prediction Scoring System)
Trend Analysis
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score
0,0018
Percentile
0,1th
Updated
Single Data Point
Only one EPSS measurement is available for this CVE. Trend analysis requires multiple data points over time.
273
Improper Check for Dropped Privileges
IncompleteCommon Consequences
Security Scopes Affected:
Access Control
Non-Repudiation
Potential Impacts:
Gain Privileges Or Assume Identity
Hide Activities
Applicable Platforms
All platforms may be affected
https://security.freebsd.org/advisories/FreeBSD-SA-26:53.ktrace.asc