CVE-2025-15576Patch(freebsd / freebsd)

MEDIUMCVSS 7.5 · HIGH

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch freebsd freebsd systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

If two sibling jails are restricted to separate filesystem trees, which is to say that neither of the two jail root directories is an ancestor of the other, jailed processes may nonetheless be able to access a shared directory via a nullfs mount, if the administrator has configured one. In this case, cooperating processes in the two jails may establish a connection using a unix domain socket and exchange directory descriptors with each other. When performing a filesystem name lookup, at each step of the lookup, the kernel checks whether the lookup would descend below the jail root of the current process. If the jail root directory is not encountered, the lookup continues. In a configuration where processes in two different jails are able to exchange file descriptors using a unix domain socket, it is possible for a jailed process to receive a directory for a descriptor that is below that process' jail root. This enables full filesystem access for a jailed process, breaking the chroot. Note that the system administrator is still responsible for ensuring that an unprivileged user on the jail host is not able to pass directory descriptors to a jailed process, even in a patched kernel.

4.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269CWE-488CWE-790

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • freebsd

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 12 mentions across 8 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 7 signals
  • Technical details provided in 9 signals
  • General: 3 classified signals
  • Peaked 5d ago at 3 mentions (2026-02-27); latest day: 2
  • 12 total mentions across 8 days

Affected systems

Vendors
Products
freebsd

2 versions affected across 1 product

Deep dive

Activity timeline12 mentions / 8d
01223Mentions · 2026-02-24: 1Mentions · 2026-02-26: 2Mentions · 2026-02-27: 3Mentions · 2026-02-28: 1Mentions · 2026-03-01: 1Mentions · 2026-03-02: 1Mentions · 2026-03-05: 1Mentions · 2026-03-09: 2Active Exploitation · 2026-02-24: 1Patch / Workaround · 2026-02-26: 2Patch / Workaround · 2026-02-27: 3Patch / Workaround · 2026-02-28: 1Patch / Workaround · 2026-03-05: 1Technical Details · 2026-02-26: 2Technical Details · 2026-02-27: 3Technical Details · 2026-02-28: 1Technical Details · 2026-03-02: 1Technical Details · 2026-03-05: 1Technical Details · 2026-03-09: 102-2402-2602-2702-2803-0103-0203-0503-09
Signal classification4 categories
Patch
758.3%
General
325.0%
Active Exploitation
18.3%
Disclosure
18.3%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-02-241
Active Exploitation1
2026-02-262
Patch2
2026-02-273
Patch3
2026-02-281
Patch1
2026-03-011
General1
2026-03-021
General1
2026-03-051
Patch1
2026-03-092
Disclosure1General1
Full discourse12 posts
  • NanoVMs@nanovms
    Active Exploitation

    multiple jail escapes in freebsd in the past month -neither of which being flagged in your favorite scanners - CVE-2025-15576 , CVE-2025-15547 If you stronger isolation - you need unikernels. https://t.co/8UMDkVw8WN

    Post summary

    The tweet reports recent jail escape exploits in FreeBSD (CVE‑2025‑15576 and CVE‑2025‑15547) that have not been detected by scanners, indicating active exploitation in the wild.

    01041240
    2.0K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Severe vulnerability in FreeBSD. CVE-2025-15576. Exploitation enables full filesystem access for a jailed process, breaking the chroot. More info: https://www.freebsd.org/security/advisories/FreeBSD-SA-26:04.jail.asc #Patch #Patch #Patch

    Post summary

    FreeBSD CVE-2025-15576 allows jailed processes to escape the chroot and access the full filesystem; patches are available via the official advisory.

    01011254
    7.2K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    FreeBSD patches a critical jail escape (CVE-2025-15576) and a kernel heap overflow (CVE-2026-3038). Learn how nullfs and routing sockets put hosts at risk. #FreeBSD #CyberSecurity #JailEscape #InfoSec #KernelSecurity #Vulnerability #SysAdmin #OpenSource https://securityonline.info/new-freebsd-vulnerabilities-allow-jail-escapes-and-kernel-panics/

    Post summary

    FreeBSD has released patches for CVE‑2025‑15576 (jail escape) and CVE‑2026‑3038 (kernel heap overflow), underscoring the risks posed by nullfs and routing sockets.

    00021319
    10.4K followersView on X
  • NanoVMs@nanovms
    General

    @xbeaudouin @_Nidouille_ not really - CVE-2025-15576 , CVE-2025-15547

    Post summary

    The tweet merely lists two CVE identifiers without providing any additional context or details.

    10010152
    2.0K followersView on X
  • iototsecnews@iototsecnews
    Patch

    FreeBSD の脆弱性 CVE-2025-15576 が FIX:jail 環境からの完全な脱出を許す可能性 https://iototsecnews.jp/2026/02/27/freebsd-vulnerability-allow-attackers-to-crash-the-entire-system/ FreeBSD の仮想化/分離機能である jail において、隔離された環境からホスト OS のファイルシステムへのアクセスが可能になる、深刻な脆弱性 CVE-2025-15576 が修正されました。jail はプロセスを特定のディレクトリ・ツリー内に閉じ込めることで、ホストや他の環境から隔離する仕組みですが、今回の欠陥により露呈したのは、この境界線を突破する具体的な手法です。この問題は、2 つの独立した兄弟関係 (sibling) にある jail が、特定の共有設定 (nullfs mount) の下で動作する際に発生します。 通常では、プロセスがアクセスするディレクトリが、jail のルートの下位にあることを、カーネルが厳格に検証しますが、2 つの jail が Unix ドメイン・ソケットを通じてディレクトリ記述子 (file descriptor) を直接やり取りする場合に、名称解決プロセスに不備が生じます。この不備を突く攻撃者は、ソケット経由でもう一方の jail からディレクトリ記述子を受け取ることで、本来はアクセスできないはずの jail 外のパスを確立できてしまいます。ご利用のチームは、ご注意ください。 #CVE202515576 #FreeBSD #Vulnerability

    Post summary

    CVE‑2025‑15576, a jail‑escape flaw in FreeBSD that could allow cross‑jail filesystem access via nullfs mounts and Unix domain sockets, has now been fixed.

    01000200
    483 followersView on X
  • 奇伟@xbeaudouin
    General

    @nanovms @_Nidouille_ https://www.freebsd.org/security/advisories/FreeBSD-SA-26:04.jail.asc https://www.freebsd.org/security/advisories/FreeBSD-SA-26:02.jail.asc CVE-2025-15576, CVE-2025-15547 exist ONLY in FreeBSD 13.5 and 14.3, not in 15.0....

    Post summary

    The tweet notes that CVE-2025-15576 and CVE-2025-15547 are present only in FreeBSD 13.5 and 14.3, not in 15.0, referencing official advisories.

    10000117
    1.1K followersView on X
  • ThreatCluster@threatcluster
    Patch

    FreeBSD issues advisory on CVE-2025-15576, a critical jail escape bug that can crash entire systems and expose host filesystems. Admins should patch now via FreeBSD-SA-26:04.jail. #Vulnerability https://threatcluster.io/cluster/critical-freebsd-vulnerabilities-allow-system-crashes-and-ja-25d99e46

    Post summary

    FreeBSD has issued an advisory for CVE‑2025‑15576, a critical jail escape vulnerability that can crash systems and expose host filesystems; administrators are advised to apply the patch immediately.

    0001053
    83 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-15576 If two sibling jails are restricted to separate filesystem trees, which is to say that neither of the two jail root directories is an ancestor of the other, jailed pr… https://www.cve.org/CVERecord?id=CVE-2025-15576

    Post summary

    A brief excerpt referencing CVE-2025-15576 that outlines a technical scenario involving sibling jails and filesystem trees, with no evidence of PoC, exploit, or patch.

    0000097
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2025-15576 Jail Chroot Escape Vulnerability in FreeBSD 14.3 and 13.5 https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-15576

    Post summary

    The post merely lists CVE-2025-15576 as a jail chroot escape issue in FreeBSD and provides a link to a vulnerability portal, offering no further technical or exploit details.

    0000052
    4.0K followersView on X
  • The Daily Tech Feed@dailytechonx
    Patch

    Urgent: Critical #FreeBSD vulnerability (CVE-2025-15576) allows jail escape and full system compromise. Administrators must patch immediately to secure systems. Link: https://thedailytechfeed.com/critical-freebsd-vulnerability-cve-2025-15576-allows-jailbreak-urgent-system-patch-required/ #Security #Vulnerability #Patch #System #Admin #Exploit #Escape #Compromise #Urgent #Server #Tech #Update #Network #Risk #Protection #Software #Threat #Breach #Alert #IT

    Post summary

    The post underscores a critical FreeBSD vulnerability (CVE-2025-15576) that permits jail escape and full system compromise, urging immediate patching of affected systems.

    000008
    249 followersView on X
  • 趣テクノロジー@omomuki_tech
    Patch

    FreeBSDに、隔離されたjail環境から攻撃者が脱出できてしまう重大な脆弱性(CVE-2025-15576)が発見されたようです。 FreeBSDの「jail」とは、プロセスを特定のディレクトリツリーに制限し、ホストシステムから隔離するためのセキュリティ機能です。 この脆弱性を悪用されると、本来は制限されているはずのjail内のプロセスがその制約を回避し、ホストシステムのファイルシステム全体への不正なフルアクセス権限を獲得できてしまいます。 これにより、攻撃者はシステムの根幹に関わるファイルへのアクセスも可能になる危険な状態となります。 この問題はシステムクラッシュを引き起こすこととも関連付けられていますが、最も危険なのはこの「脱獄(ジェイルブレイク)」による権限昇格です。 管理者の方は、緊急のパッチ適用が強く推奨されています。 #FreeBSD #脆弱性 #セキュリティ https://cybersecuritynews.com/freebsd-vulnerability/

    Post summary

    A newly discovered jail escape vulnerability (CVE-2025-15576) in FreeBSD enables attackers to escape to the host filesystem and gain full access, and administrators are urged to apply the emergency patch.

    0000032
    234 followersView on X
  • kantan.news@KantanNewsX
    Patch

    FreeBSD sistemlerinde keşfedilen kritik CVE-2025-15576 zafiyeti, saldırganların izole edilmiş jail ortamlarından kaçarak tüm dosya sistemini ele geçirmesine neden oluyor. Geçici bir çözümü olmayan bu açık için acil yama gerekiyor. Haberin detayı: https://kantan.news/x_article.php?slug=freebsd-de-tehlikeli-jailbreak-a-tm-sistem-tehlikede-olabilir

    Post summary

    A critical FreeBSD flaw (CVE‑2025‑15576) enables jail escape and full filesystem takeover, and no temporary workaround exists—an urgent patch is required.

    0000077
    811 followersView on X
CPE platform detail19 entries

19 of 19 entries

PartVendorProductVersionTarget SWTarget HW
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd13.5--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--
OSfreebsdfreebsd14.3--

Explore more