Executive brief
A vulnerability in a FreeBSD networking library could allow restricted applications to bypass security limits. This library is used to manage network permissions for programs running in a secure 'sandbox' environment. If exploited, a program that was supposed to have limited network access could grant itself broader permissions, potentially allowing it to communicate with unauthorized network addresses.
Technical details
A vulnerability exists in the libcap_net service of FreeBSD's libcasper(3) framework due to improper handling of limitation lists. When an application attempts to update its capability limits, omitting a key that was present in the previous limit set causes the service to treat that key as 'allow any' rather than rejecting the expansion. This violates the Capsicum capability model, which dictates that subsequent limit adjustments may only narrow permissions. An attacker with the ability to execute code within a Capsicum-sandboxed process using libcap_net can exploit this to gain unauthorized network access (e.g., binding or connecting to restricted addresses). The issue is resolved in FreeBSD 15.0-STABLE, 14.4-STABLE, and relevant RELEASE-p patches.
Affected products
- FreeBSD Project FreeBSD 15.0-STABLE, 15.0-RELEASE-p9, 14.4-STABLE, 14.4-RELEASE-p5, 14.3-RELEASE-p14
Timeline
- 2026-05-19: patched: Initial correction in stable/15 and stable/14 branches.
- 2026-05-20: advisory: FreeBSD Security Advisory SA-26:24.cap_net published.
- 2026-05-21: disclosed: CVE-2026-45254 published to NVD.