Feed
FreeBSD

A credential-switch policy can set the wheel group on FreeBSD 15

Brief

Hosts that do not load a mac_do ruleset are not affected.

Notes

FreeBSD-SA-26:59.mac_do CVE-2026-58092. Unauthorized credential switching. Further root depends on the ruleset. 15.0 and later only. Workaround in the advisory: no ruleset, or rules that name a target group. Credits: Hazley Samsudin of GovTech CSG.

releng/15.1 97b7439e3b06. releng/15.0 00036dad647f. stable/15 ae27dff4710b. Not on 14.x. In 15.1-p3 and 15.0-p13.

Commit 97b7439e3b060d350cbd85321dd7e315907f366a

Sources