CVE-2025-15547

HIGH

FreeBSD Jail - Privilege Escalation

Title source: llm
STIX 2.1

Description

By default, jailed processes cannot mount filesystems, including nullfs(4). However, the allow.mount.nullfs option enables mounting nullfs filesystems, subject to privilege checks. If a privileged user within a jail is able to nullfs-mount directories, a limitation of the kernel's path lookup logic allows that user to escape the jail's chroot, yielding access to the full filesystem of the host or parent jail. In a jail configured to allow nullfs(4) mounts from within the jail, the jailed root user can escape the jail's filesystem root.

Scores

CVSS v3 8.8
EPSS 0.0001
EPSS Percentile 3.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-269
Status published
Products (4)
freebsd/freebsd 13.5 (9 CPE variants)
freebsd/freebsd 14.3 (8 CPE variants)
FreeBSD/FreeBSD 13.5-RELEASE - p9
FreeBSD/FreeBSD 14.3-RELEASE - p8
Published Mar 09, 2026
Tracked Since Mar 09, 2026