Vulnerability Details CVE-2026-5398
The implementation of TIOCNOTTY failed to clear a back-pointer from the structure representing the controlling terminal to the calling process' session. If the invoking process then exits, the terminal structure may end up containing a pointer to freed memory.
A malicious process can abuse the dangling pointer to grant itself root privileges.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 4.3%
CVSS Severity
CVSS v3 Score 8.4
Products affected by CVE-2026-5398
-
cpe:2.3:o:freebsd:freebsd:13.5
-
cpe:2.3:o:freebsd:freebsd:14.3
-
cpe:2.3:o:freebsd:freebsd:14.4
-
cpe:2.3:o:freebsd:freebsd:15.0