CVE-2020-25582

HIGH

FreeBSD Race Condition via ptrace Attachment

Title source: llm
STIX 2.1

Description

In FreeBSD 12.2-STABLE before r369334, 11.4-STABLE before r369335, 12.2-RELEASE before p4 and 11.4-RELEASE before p8 when a process, such as jexec(8) or killall(1), calls jail_attach(2) to enter a jail, the jailed root can attach to it using ptrace(2) before the current working directory is changed.

References (2)

Core 2
Core References
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20210423-0003/

Scores

CVSS v3 8.7
EPSS 0.0039
EPSS Percentile 60.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N

Details

CWE
CWE-362
Status published
Products (2)
freebsd/freebsd 11.4 (8 CPE variants)
freebsd/freebsd 12.2 (4 CPE variants)
Published Mar 26, 2021
Tracked Since Feb 18, 2026