A critical use-after-free vulnerability, identified as CVE-2026-58093, has been discovered in the FreeBSD kernel's tty ioctl handlers. The vulnerability arises from a race condition where the TIOCSCTTY ioctl handler fails to revalidate the terminal's state after reacquiring the tty lock. This flaw could allow an unprivileged local user to escalate privileges by exploiting the condition to link a concurrently destroyed terminal to the calling process's session. AI
RANK_REASON Discovery of a specific CVE vulnerability in an operating system kernel. [lever_c_demoted from research: ic=1 ai=0.4]
Read on Mastodon — fosstodon.org →
AI-generated summary · Google Gemini · from 1 sources. How we write summaries →