Description
By default, jailed processes cannot mount filesystems, including nullfs(4). However, the allow.mount.nullfs option enables mounting nullfs filesystems, subject to privilege checks. If a privileged user within a jail is able to nullfs-mount directories, a limitation of the kernel's path lookup logic allows that user to escape the jail's chroot, yielding access to the full filesystem of the host or parent jail. In a jail configured to allow nullfs(4) mounts from within the jail, the jailed root user can escape the jail's filesystem root.
Scores
CVSS v3
8.8
EPSS
0.0001
EPSS Percentile
3.4%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-269
Status
published
Products (4)
freebsd/freebsd
13.5 (9 CPE variants)
freebsd/freebsd
14.3 (8 CPE variants)
FreeBSD/FreeBSD
13.5-RELEASE - p9
FreeBSD/FreeBSD
14.3-RELEASE - p8
Published
Mar 09, 2026
Tracked Since
Mar 09, 2026