Impact
The flaw lies in the handling of the TIOCSCTTY ioctl, where the tty lock is released to obtain the process tree lock and is not correctly revalidated upon reacquisition. This race condition allows a local attacker to link a terminal that is concurrently being destroyed to the victim process's session, effectively creating a use‑after‑free scenario. An unprivileged user can exploit this flaw to elevate privileges on the system.
Affected Systems
The vulnerability affects the FreeBSD operating system. Specific version information is not disclosed in the advisory.
Risk and Exploitability
No CVSS score or EPSS value is publicly available, but the described privilege escalation indicates a high impact risk. The vulnerability is not listed in the CISA KEV catalog, suggesting that no widespread exploitation is reported yet, yet the severity of the flaw warrants vigilance and prompt remediation.
OpenCVE Enrichment