Arbitrary file overwrite vulnerability in FreeBSD

A local privilege escalation vulnerability in FreeBSD has been disclosed. It is known as BUMSRAKETE and tracked as CVE-2026-45257 and FreeBSD-SA-26:26.ktls. Tenable rates it as High, with a CVSS v3 score of 7.1. The issue affects FreeBSD 13.0 and later on affected architectures, including supported 13.x, 14.x and 15.0 releases prior to the relevant security fixes. It is caused by a flaw in FreeBSD's kernel TLS receive path, where encrypted data may be decrypted directly into the page cache of a file rather than into a private buffer. In practice, an unprivileged local user who can read a file may be able to overwrite that file's contents with chosen data. This can bypass normal file permissions and file flags, and may allow privilege escalation by modifying a setuid binary or another trusted file. Technical details and a working proof of concept have been published.

What this means for your organisation

Local privilege escalation is often deprioritised because the attacker "already has to be inside". In practice, this is exactly the step that turns a limited compromise into full control of a server. FreeBSD is commonly used in network appliances, storage systems and firewalls, that is, systems where one compromised host can affect segments far beyond itself.

Berigo recommends

  • Map where FreeBSD is actually running in your environment, including vendor appliances built on FreeBSD.
  • Apply the security fixes from the FreeBSD project on affected versions.
  • Limit who holds local login access on servers in this role, and remove accounts that are no longer needed.
  • Monitor changes to setuid binaries and other trusted files as part of integrity control.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch