Feed
FreeBSD

Performance counters could keep watching after a privilege jump

Brief

The advisory calls this a local policy bypass, not privilege escalation.

Notes

FreeBSD-SA-26:56.hwpmc CVE-2026-58089. Unprivileged process attaching counters across exec of a setuid or setgid image. Affects all supported versions. Systems that do not use hwpmc are not affected. Credits: Alexander Leidinger.

releng/15.1 e034ae898328. releng/15.0 57a2373f86ac. releng/14.4 97e1e603bd40. stable/15 87bb4aa63ac7, stable/14 5eaecdb275d3. Tags 15.1-p3 / 15.0-p13 / 14.4-p9 are this batch, not a separate release story.

Commit e034ae898328ad30bdbc0abb75d5f6d661e74e8b

Sources