Impact
The flaw lies in the handling of the TIOCSCTTY ioctl, where the tty lock is released to obtain the process tree lock and is not correctly revalidated upon reacquisition. This race condition allows a local attacker to link a terminal that is concurrently being destroyed to the victim process's session, effectively creating a use‑after‑free scenario. An unprivileged user can exploit this flaw to elevate privileges on the system.
Affected Systems
The vulnerability affects the FreeBSD operating system. Specific version information is not disclosed in the advisory.
Risk and Exploitability
The CVSS score of 7 indicates moderate to high severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, indicating no widespread exploitation has been reported. The described privilege escalation provides a high impact risk, warranting vigilance and prompt remediation.
OpenCVE Enrichment