Home

Description

In the case of the cap_net service, when a key present in the old limit was omitted from the new limit, the missing key was treated as "allow any" instead of being rejected. In certain scenarios, an application that had previously restricted a subset of network operations could ask for a new limit that extended the permissions of the process.

PUBLISHED Reserved 2026-05-11 | Published 2026-05-21 | Updated 2026-05-21 | Assigner freebsd

Problem types

CWE-269 Improper Privilege Management

Product status

Default status
unknown

15.0-RELEASE (release) before p9
affected

14.4-RELEASE (release) before p5
affected

14.3-RELEASE (release) before p14
affected

Credits

Joshua Rogers of AISLE Research Team finder

References

security.freebsd.org/advisories/FreeBSD-SA-26:24.cap_net.asc vendor-advisory

cve.org (CVE-2026-45254)

nvd.nist.gov (CVE-2026-45254)

Download JSON