CVE-2026-58086: ktrace(2) privilege incorrectly validated in jails

Published Aug 19, 2026
·
Updated

As an inadvertent side effect of an unrelated code change, PRIVKTRACE was always denied to a jailed root user. Tracing configured by a jailed root user was therefore not flagged as privileged.

An unprivileged user in a jail that has permission to debug the target process can modify the jailed root user's ktrace(2) flags, or disable tracing outright. A jailed root user therefore cannot reliably trace unprivileged processes.

Affected Software

1 affected component
FreeBSD jails

Event History

Aug 19, 2026
CVE Published
via MITRE·07:42 AM
Data Sourced
via MITRE·07:42 AM
DescriptionWeakness

Frequently Asked Questions

1

Who can interfere with tracing configured by a jailed root user?

An unprivileged user within the same jail can do so if they have permission to debug the process being traced. They can modify the jailed root user's ktrace(2) flags or disable tracing entirely.

2

Does this let an unprivileged jail user trace arbitrary processes?

No. The described interference requires that the unprivileged user already has permission to debug the target process.

3

What is the operational impact for jailed root users?

A jailed root user cannot rely on ktrace(2) to trace unprivileged processes, because another eligible user in the jail can alter or stop that tracing.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203