Junglewise Threat Intelligence

CVE-2026-58089: FreeBSD hwpmc privilege escalation in setuid exec

CVE-2026-58089 · Severity: high · CVSS 7.8 · Published 2026-08-26

Technologies: Freebsd. Vendors: Freebsd.

Executive brief

FreeBSD's hardware performance monitoring counter (hwpmc) driver is designed to prevent unprivileged users from monitoring privileged processes when they execute setuid or setgid binaries. A logic error in the driver bypasses this protection, allowing an unprivileged local attacker to continue observing a process even after it gains elevated privileges. This could expose sensitive execution details and performance data from privileged programs.

Technical details

The vulnerability exists in the hwpmc(4) driver's handling of credential transitions during execve(2) calls. When a process executes a setuid or setgid binary, hwpmc should detach performance monitoring counters (PMCs) attached by unprivileged users; however, an inverted conditional check causes this detachment logic to fail. An unprivileged local user can attach PMCs to a process they own, and after that process executes a setuid/setgid binary, the attacker retains the ability to monitor performance data that should no longer be accessible. This is a local privilege escalation requiring no special privileges to attach PMCs initially, but it violates the intended security boundary between privilege levels. Patches are available for all supported FreeBSD branches (14.4, 15.0, 15.1).

Affected products

  • FreeBSD FreeBSD All supported versions (14.x, 15.x)

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched

References

Related threats