Description
In the case of the cap_net service, when a key present in the old limit was omitted from the new limit, the missing key was treated as "allow any" instead of being rejected. In certain scenarios, an application that had previously restricted a subset of network operations could ask for a new limit that extended the permissions of the process.
Problem types
CWE-269 Improper Privilege Management
Product status
15.0-RELEASE (release) before p9
14.4-RELEASE (release) before p5
14.3-RELEASE (release) before p14
Credits
Joshua Rogers of AISLE Research Team
References
security.freebsd.org/advisories/FreeBSD-SA-26:24.cap_net.asc