54 ms·
Local privilege escalation via execve()
- rvz 5mo ago> IV. Workaround > No workaround is available. Oh dear.
- itsthefrank 5mo ago> V. Solution > Upgrade your vulnerable system to a supported FreeBSD stable or release / security branch (releng) dated after the correction date, and reboot the system. Not everyone can just freebsd-update and reboot, so yes, "Oh dear." is a good response to this.
- epcoa 5mo agoAnyone relying on a 30+ year old monolith kernel written in C to not have some exploitable LPEs lurking should stay in basket weaving and out of sysadmin.
- itsthefrank 5mo agoNot sure why the snark but if people are running FreeBSD then they should be...basket weaving instead of using it? Yes, the correct solution is to patch and reboot but not everyone is in a place to jump and do that which is why a temp workaround, if possible, would be welcome
- wswin 5mo agoI think good system should be prepared to do a reboot in a short notice. Even some long running jobs can have a pause mechanism.
- epcoa 5mo agoThere was no snark. If you have something of importance running and the inevitable discovery of an LPE is something you don’t have defense for or can quickly mitigate you’re doing a bad job as a sysadmin. For all general purpose OS in common use today that usually means patch and reboot should be an NBD workaround.
- cyberpunk 5mo agoYep. You should treat any system where non-admins regularly login as basically insecure/owned and rig your architecture appropriately. TBH -- I don't have any of these kinds of boxes anymore. Who is really running anything like this in 2026 and for what purpose?
- jmspring 5mo agoStability of ecosystem. No systemd. Native ZFS. Jails over Docker. Been using it for 20+ years and it’s my preferred server OS.
- cyberpunk 5mo agoNo, I mean do you run FreeBSD boxes where users who should not ever assume root access actually login to do tasks? My point is that if you do, you probably shouldn't run, for e.g applications which need production db credential, or hold sensitive data on these boxes, or .. whatever. Edit: I use FreeBSD extensively, for various things -- but shell access to them is restricted to the sysadmins..
- CoolCold 5mo agoHard to tell about FreeBSD, it's basically extincted, but think of webhosting servers, wordpress, cPanel/Plesk and alike. often it's ssh'able with things like rbash and other restrictions and almost always you, well, can run something there (as you can edit php/other files right from web management ui). Hordes of this (in Linux world).
- jmspring 5mo agoExtinct? Far from, just doesn’t draw the crowd/press Linux does. An OS used as a stable server OS workhorse with exceptional ZFS support and doesn’t have to push for the desktop market doesn’t mean it’s extinct. I’ve run FreeBSD on stinkpads back in the early 2000s fine. I prefer MacOS these days as a daily driver - hardware quality. But server OS is FreeBSD. Void when I need Cuda/docker/etc. (Yes, FreeBSD has docker support, but just use Linux if needing that.
- yjftsjthsd-h 5mo ago...as opposed to what, exactly? Linux is a 34 y.o. monolithic kernel in C, the BSDs are all forked from the same base (386BSD) of around the same age, XNU is 29 years old (and also heavily based on BSD code while also throwing in mach code) in C and other languages,...
- raddan 5mo agoThe 33 year old Windows NT kernel, duh.
- deleted 5mo ago[deleted]
- skydhash 5mo agoWhy can't they? Upgrading and rebooting is kinda the standard response for most security issues. So I would expect something like Ansible's playbooks for this exact scenario. You might also have it setup as a staggered rollout.
- paulddraper 5mo agoWhat prevents it?
- tptacek 5mo agoDoes this vulnerability not rely on SUID binaries?
- cperciva 5mo agoI don't think so? It's a buffer overflow in the system call.
- tptacek 5mo agoI just read that it was spilling into argv or something and assumed the vector was somehow injecting arguments or something.
- cperciva 5mo agoThe exploit is injecting environment variables, but yes, close enough. You need someone to call execve as root in order to become root, but you don't need a setuid binary.
- rsync 5mo agoI am reading: "When the timing aligns, the trigger's buggy memmove causes K+1 to self-overwrite, replacing sshd-session's real environment with the preseed payload. sshd-session's exec_copyout_strings copies LD_PRELOAD=/tmp/evil.so to the new process's stack, the runtime linker loads evil.so, and its constructor copies /bin/sh to /tmp/rootsh and sets it suid root. My human's unprivileged user runs /tmp/rootsh -p and gets a root shell." ... so at the very end of the exploit chain, is /tmp/rootsh required to be suid root before it is finally run to get the root shell ? ... or is the exploit already achieved and /tmp/rootsh is just an arbitrary indicator ?
- tptacek 5mo agoOne of the authors is on this subthread correcting me. :)
- 5mo ago
- wolvoleo 5mo agoWhy? Just update.
- ActorNightly 5mo agoI really am starting to think that the level of technical understanding on HN is so low that when readers see an exploit like this, they imagine basically the cult classic movie "Hackers" in their heads where some guy hacks into any machine of their choosing.
- jeffrallen 5mo agoIV. Workaround Accept that everything is broken and terrible and yet somehow find a way to keep a sense of humor and smile about it.
- doublerabbit 5mo agoLinux is on their second and FreeBSD is on their first. How many is Windows on?
- pjmlp 5mo agoPlenty, Microsoft has security teams whose job is to attack Windows. Naturally they don't do blog posts about what they find.
- hnlmorg 5mo agoYou talk as if Windows is the only OS that has red teams attacking the system when clearly that isn’t even remotely true.
- asveikau 5mo agoNo, they're saying security work happens in the Windows world but not as much in the open, due to the closed source nature.
- pjmlp 5mo agoI talk about that because it is public, and the OP mentioned Windows. It he talked about Android, I would have mentioned Project Zero. Don't twist the meaning of posts.
- murderfs 5mo agoLocal privilege escalation is largely irrelevant on Windows because basically no one uses it in a multi-user system, and application sandboxing is effectively nonexistent.
- TZubiri 5mo agoI get that multiple human users on a same machine is rare nowadays, and that per-app users were never a thing. But windows still has a root and a lower privilege user. You typically need to click on "run as admin" to elevate privileges to, for example, alter system binaries.
- cyberpunk 5mo agoThis is from April 28th, it was patched in 15.0R-p7.
- itsthefrank 5mo ago-p8 is the current patch level for 15.0-RELEASE so if people have been keeping on top of patching this is already two reboots in the past.
- loeg 5mo ago[flagged]
- broken-kebab 5mo agoOr in other words, the response is well-coordinated so cperciva's bragging is justified, isn't it?
- cperciva 5mo agoIndeed, I was thinking about this precise issue when I made the point that corresponding issues get handled much better in FreeBSD than in Linux.
- bch 5mo agoIts like rain on your wedding day - not actually ironic, just unfortunate.
- stackghost 5mo agoA not-insignificant chunk of the userbase of the various BSDs is there because they were turned off of Linux after controversial things like Gnome 3, systemd being shoved down users' throats despite being a broken mess, wayland (though nobody was as arrogant about wayland as Poettering was about systemd), etc. All that to say, the BSD userbase as a sizeable subset that are there for countercultural reasons, rather than technical. These are the people who buy into, say, OpenBSD's vaunted security reputation, or believe that "linux bad because reasons", so you're always going to get people in here bragging, because "not using linux" has become part of their identity. I run a mix of FreeBSD and Linux on my personal devices. The ground truth is that FreeBSD is yet another unix-like OS written in C, and thus not immune from the types of bugs that stem from that lineage. None of the BSD distros are materially more secure or better than a properly-configured and patched Linux.
- deleted 5mo ago[deleted]
- cryptbe 5mo agoNice to randomly encounter our own work here. Check out our blog post for a fun walkthrough: https://blog.calif.io/p/cve-2026-7270-how-i-get-root-on-freebsd https://blog.calif.io/p/cve-2026-7270-how-i-get-root-on-free... AI-generated working exploit, write-up and prompts: https://github.com/califio/publications/tree/main/MADBugs/freebsd-CVE-2026-7270 https://github.com/califio/publications/tree/main/MADBugs/fr...
- j16sdiz 5mo agoYour bot's blog is above average bot level. I am sure you have spend lots of time to make your bot works that great.
- i-LINK 5mo ago"our" is a stretch. Not only because you're giving an algorithm personhood, but because you didn't do any of the real work. So you could instead say that it's "nice to randomly encounter what I prompted an instance of [brand of artificially intelligent dowsing rod] to do". There's your chance to claim ownership; you can plainly state that you're the person who pressed the button.
- yunnpp 5mo agoThey are fixing bugs in open source projects. What are you doing? You're not even tapping that button.
- tptacek 5mo agoCalif is just killing it these past couple months. Reminder that Calif is Thai Duong's new firm.
- wolvoleo 5mo agoOof that's a pretty big one, I didn't realise but I had already updated anyway.
- 0xbadcafebee 5mo agomemmove(args->begin_argv + extend, args->begin_argv + consume, args->endp - args->begin_argv + consume); // ← bug C code like this is why we can't have nice things. Arithmetic operation in the arguments of a dangerous function call with no explicit bounds check.
- sethops1 5mo ago"I just don't write bugs" Yeah.
- jahanzeb1018 5mo ago[flagged]
- Groxx 5mo ago- args->endp - args->begin_argv + consume); + args->endp - (args->begin_argv + consume)); tbh I've considered simply banning math-operator-precedence in projects I work on, and requiring all mixed-operator code to use parenthesis or split to multiple statements. I do that myself, at least. I've seen so many mistakes from it, and seen people spend so much pointless and avoidable time deciphering and verifying it, it really doesn't seem worth it (in most code) for the extremely minor character savings.
- om2 5mo ago- and + operators have the same precedence. And a similar bug is possible if the operators were the same (both -). So I’m not sure it’s right to blame this on operator precedence or mixed operators. It’s just that, ultimately, the “consume” needs to be subtracted, not added.
- Groxx 5mo agoNon-mixed always goes strictly left to right, regardless of the operator, which I haven't seen anywhere near as much struggling with. But yes, I personally parenthesize `a-b-c` explicitly, because it's not worth it for me to read and wonder if parenthesizing order matters later. Costs less than a second to write, saves a second or ten each time I read it - that's an excellent tradeoff imo, and is a trivial pattern to follow. (Associative operators are fine, obviously)
- simonreiff 5mo agoI agree with explicit parentheses but please be careful about assuming associativity! The risk when handling floating-point arithmetic in particular is that associativity breaks, and suddenly a + (b + c) does NOT equal (a + b) + c. Not only can these lead to unexpected and hard-to-trace failure patterns, but depending on the details, they also can introduce memory overflow/underflow vulnerabilities.
- chuckadams 5mo ago
- dnw 5mo agoA CVE for exeCVE()
- jeffrallen 5mo agoPuttin' the CVE in execve.
- kkyktkrkekk 5mo agoWho would have thought.
- andrew_kwak 5mo ago[flagged]