Join Nostr
2026-05-07 19:29:13 UTC

:rainbowCrow: on Nostr: RE: I'm too tired to troll the whole "FreeBSD had a vuln ZOMG" thing so maybe some of ...

RE: https://swecyb.com/@orlysec/116534940626646604

I'm too tired to troll the whole "FreeBSD had a vuln ZOMG" thing so maybe some of you would rather do it today.
(calif.io) CVE-2026-7270: Root Privilege Escalation in FreeBSD via Kernel Memory Corruption in execve()

New critical LPE in FreeBSD: CVE-2026-7270 enables root access via a one-character error in `execve()` kernel handling. Exploit targets `sshd-session` with `LD_PRELOAD` injection through a race condition.

In brief - CVE-2026-7270 is a local privilege escalation flaw in FreeBSD (since 2013) caused by a sign error in `execve()` memory handling. Attackers can corrupt kernel memory during shebang script execution, inject `LD_PRELOAD`, and gain root via `sshd-session`. Affects default installations.

Technically - The bug in `sys/kern/kern_exec.c` (`exec_args_adjust_args`) miscalculates `memmove` size (`+ consume` instead of `- consume`), causing a 2,024-byte overflow into an adjacent `exec_map` entry. Exploit preseeds kernel memory at offset 265,166 bytes to replace `sshd-session` environment with `LD_PRELOAD=/tmp/evil.so`. Race condition optimized via fragmented argument strings to slow `execve` calls. Challenges include avoiding `MADV_FREE` under memory pressure and a 3.1% panic risk. PoC achieves root in seconds.

Source: https://blog.calif.io/p/cve-2026-7270-how-i-get-root-on-freebsd

#Cybersecurity #ThreatIntel