In FreeBSD 13.0-STABLE before n245118, 12.2-STABLE before r369552, 11.4-STABLE before r369560, 13.0-RC5 before p1, 12.2-RELEASE before p6, and 11.4-RELEASE before p9, a superuser inside a FreeBSD jail configured with the non-default allow.mount permission could cause a race condition between the lookup of ".." and remounting a filesystem, allowing access to filesystem hierarchy outside of the jail.
2021-04-07T15:15:13.013
2024-11-21T05:18:10.463
Modified
CVSSv3.1: 7.5 (HIGH)
AV:L/AC:H/Au:N/C:C/I:C/A:C
1.9
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | freebsd | freebsd | < 11.4 | Yes |
Operating System | freebsd | freebsd | < 12.2 | Yes |
Operating System | freebsd | freebsd | 11.4 | Yes |
Operating System | freebsd | freebsd | 11.4 | Yes |
Operating System | freebsd | freebsd | 11.4 | Yes |
Operating System | freebsd | freebsd | 11.4 | Yes |
Operating System | freebsd | freebsd | 11.4 | Yes |
Operating System | freebsd | freebsd | 11.4 | Yes |
Operating System | freebsd | freebsd | 11.4 | Yes |
Operating System | freebsd | freebsd | 11.4 | Yes |
Operating System | freebsd | freebsd | 11.4 | Yes |
Operating System | freebsd | freebsd | 12.2 | Yes |
Operating System | freebsd | freebsd | 12.2 | Yes |
Operating System | freebsd | freebsd | 12.2 | Yes |
Operating System | freebsd | freebsd | 13.0 | Yes |
Operating System | freebsd | freebsd | 13.0 | Yes |
Operating System | freebsd | freebsd | 13.0 | Yes |
Operating System | freebsd | freebsd | 13.0 | Yes |
Operating System | freebsd | freebsd | 13.0 | Yes |
Operating System | freebsd | freebsd | 13.0 | Yes |
Operating System | freebsd | freebsd | 13.0 | Yes |
Operating System | freebsd | freebsd | 13.0 | Yes |
Operating System | freebsd | freebsd | 13.0 | Yes |