Executive brief
A security vulnerability exists in the FreeBSD operating system's networking component responsible for IPv6 traffic filtering. A local user with standard access could exploit this flaw to gain elevated administrative privileges (root access). This could allow an attacker to take full control of the system, access sensitive data, or disrupt operations.
Technical details
A use-after-free (UAF) vulnerability exists in the FreeBSD kernel's IPV6_MSFILTER socket option handler within the ip6_multicast module. The vulnerability occurs because the handler drops a serializing lock to copy the source-filter list from userspace and subsequently reacquires it. During this race window, a concurrent thread can free the multicast filter structure, resulting in the handler operating on a stale pointer. A local, unprivileged attacker can exploit this race condition to achieve kernel-mode code execution and privilege escalation. The issue is addressed in FreeBSD 15.0-RELEASE-p10, 14.4-RELEASE-p6, and 14.3-RELEASE-p15.
Affected products
- FreeBSD FreeBSD 15.0-RELEASE before p10, 14.4-RELEASE before p6, 14.3-RELEASE before p15
Timeline
- 2026-06-09: patched: Correction dates for various branches provided in advisory.
- 2026-06-09: advisory: FreeBSD Project issues SA-26:29.ip6_multicast.asc.
- 2026-06-27: disclosed: CVE-2026-49412 published to NVD.