CVE-2025-15547General(freebsd / freebsd)

LOWCVSS 8.8 · HIGH

Exploitation ongoing with high activity in latest observed window (3 mentions)

Immediate actions

  • Prioritize remediation for freebsd freebsd systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

By default, jailed processes cannot mount filesystems, including nullfs(4). However, the allow.mount.nullfs option enables mounting nullfs filesystems, subject to privilege checks. If a privileged user within a jail is able to nullfs-mount directories, a limitation of the kernel's path lookup logic allows that user to escape the jail's chroot, yielding access to the full filesystem of the host or parent jail. In a jail configured to allow nullfs(4) mounts from within the jail, the jailed root user can escape the jail's filesystem root.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • freebsd

Threat summary

  • Active exploitation appears in 1 classified signals
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 2 signals
  • General: 3 classified signals
  • Disclosure: 2 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-03-09)
  • 6 total mentions across 4 days

Affected systems

Vendors
Products
freebsd

2 versions affected across 1 product

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-02-24: 1Mentions · 2026-03-01: 1Mentions · 2026-03-02: 1Mentions · 2026-03-09: 3Active Exploitation · 2026-02-24: 1Technical Details · 2026-03-09: 202-2403-0103-0203-09
Signal classification3 categories
General
350.0%
Disclosure
233.3%
Active Exploitation
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-241
Active Exploitation1
2026-03-011
General1
2026-03-021
General1
2026-03-093
Disclosure2General1
Full discourse6 posts
  • NanoVMs@nanovms
    Active Exploitation

    multiple jail escapes in freebsd in the past month -neither of which being flagged in your favorite scanners - CVE-2025-15576 , CVE-2025-15547 If you stronger isolation - you need unikernels. https://t.co/8UMDkVw8WN

    Post summary

    The tweet reports recent jail escapes in FreeBSD linked to CVE-2025-15576 and CVE-2025-15547, indicating active exploitation in the wild, but provides no technical details or mitigation information.

    01041240
    2.0K followersView on X
  • NanoVMs@nanovms
    General

    @xbeaudouin @_Nidouille_ not really - CVE-2025-15576 , CVE-2025-15547

    Post summary

    The tweet merely lists two CVE identifiers without providing any additional context, technical details, or actionable information.

    10010152
    2.0K followersView on X
  • 奇伟@xbeaudouin
    General

    @nanovms @_Nidouille_ https://www.freebsd.org/security/advisories/FreeBSD-SA-26:04.jail.asc https://www.freebsd.org/security/advisories/FreeBSD-SA-26:02.jail.asc CVE-2025-15576, CVE-2025-15547 exist ONLY in FreeBSD 13.5 and 14.3, not in 15.0....

    Post summary

    The tweet references FreeBSD security advisories for CVE-2025-15576 and CVE-2025-15547, noting they affect only FreeBSD 13.5 and 14.3, not 15.0.

    10000117
    1.1K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-15547 By default, jailed processes cannot mount filesystems, including nullfs(4). However, the allow.mount.nullfs option enables mounting nullfs filesystems, subject to pr… https://www.cve.org/CVERecord?id=CVE-2025-15547

    Post summary

    The post reveals that jailed processes lack default filesystem mounting privileges and that the allow.mount.nullfs option can enable nullfs mounting, providing basic technical context for CVE‑2025‑15547 without any exploitation or patch information.

    0000098
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-15547 Jail Escape Vulnerability in FreeBSD via NullFS Mount Path Lookup Logic https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-15547

    Post summary

    The post announces a newly identified jail escape vulnerability in FreeBSD involving NullFS mount path lookups, but provides no Proof‑of‑Concept, exploit details, or mitigation.

    0000064
    4.0K followersView on X
  • VulDB 🛡@vuldb
    General

    The severity is increased for this new vulnerability affecting FreeBSD (CVE-2025-15547) https://vuldb.com/?id.349824

    Post summary

    The text notes a severity increase for a new FreeBSD vulnerability (CVE-2025-15547) but provides no technical, exploit, or mitigation details.

    00000107
    2.1K followersView on X
CPE platform detail17 entries

17 of 17 entries

PartVendorProductVersionTarget SWTarget HW
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--

Explore more