CVE-2026-5398
HIGH EPSS 6.1%
Published Apr 22, 20262mo ago · Modified Jun 17, 20261w ago
8.4 CVSS 3.1
Published Apr 22, 2026 2mo ago
Last Modified Jun 17, 2026 1w ago
Description
The implementation of TIOCNOTTY failed to clear a back-pointer from the structure representing the controlling terminal to the calling process' session. If the invoking process then exits, the terminal structure may end up containing a pointer to freed memory. A malicious process can abuse the dangling pointer to grant itself root privileges.
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Attack Vector Local
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality High
Integrity High
Availability High
Threat Intelligence
EPSS Exploit Probability
6.1% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available
Weaknesses 1
CWE-416 Use After Free Memory Safety
Affected Products 33
| Vendor | Product | Version | Range |
|---|---|---|---|
| freebsd | freebsd | 13.5 | any |
| freebsd | freebsd | 13.5 | any |
| freebsd | freebsd | 13.5 | any |
| freebsd | freebsd | 13.5 | any |
| freebsd | freebsd | 13.5 | any |
| freebsd | freebsd | 13.5 | any |
| freebsd | freebsd | 13.5 | any |
| freebsd | freebsd | 13.5 | any |
| freebsd | freebsd | 13.5 | any |
| freebsd | freebsd | 13.5 | any |
| freebsd | freebsd | 13.5 | any |
| freebsd | freebsd | 13.5 | any |
| freebsd | freebsd | 13.5 | any |
| freebsd | freebsd | 14.3 | any |
| freebsd | freebsd | 14.3 | any |
| freebsd | freebsd | 14.3 | any |
| freebsd | freebsd | 14.3 | any |
| freebsd | freebsd | 14.3 | any |
| freebsd | freebsd | 14.3 | any |
| freebsd | freebsd | 14.3 | any |
| freebsd | freebsd | 14.3 | any |
| freebsd | freebsd | 14.3 | any |
| freebsd | freebsd | 14.3 | any |
| freebsd | freebsd | 14.3 | any |
| freebsd | freebsd | 14.4 | any |
| freebsd | freebsd | 14.4 | any |
| freebsd | freebsd | 14.4 | any |
| freebsd | freebsd | 15.0 | any |
| freebsd | freebsd | 15.0 | any |
| freebsd | freebsd | 15.0 | any |
| freebsd | freebsd | 15.0 | any |
| freebsd | freebsd | 15.0 | any |
| freebsd | freebsd | 15.0 | any |
References 1
- security.freebsd.org https://security.freebsd.org/advisories/FreeBSD-SA-26:10.tty.asc
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.