7.8 CVE-2026-58089
When a process calls execve(2) to execute a setuid or setgid image, hwpmc(4) is supposed to detach PMCs owned by unprivileged processes. An inverted check meant that this scenario was not handled properly.
An unprivileged local user who has attached PMCs to a process can continue monitoring it after the process executes a setuid or setgid binary, contrary to the intended policy.
https://nvd.nist.gov/vuln/detail/CVE-2026-58089
Categories
CWE-273 : Improper Check for Dropped Privileges
If the drop fails, the product will continue to run with the raised privileges, which might provide additional access to unprivileged users.
References
AFFECTED (from MITRE)
| Vendor |
Product |
Versions |
| FreeBSD |
FreeBSD |
- 15.1-RELEASE < p3 [affected]
- 15.0-RELEASE < p13 [affected]
- 14.4-RELEASE < p9 [affected]
|
| © 2022 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. |
CPE
REMEDIATION
EXPLOITS
Exploit-db.com
| id |
description |
date |
|
| No known exploits |
POC Github
Other Nist (github, ...)
CAPEC
Common Attack Pattern Enumerations and Classifications
| id |
description |
severity |
| No entry |
Cybersecurity needs ?
Strengthen software security from the outset with our DevSecOps expertise
Integrate security right from the start of the software development cycle for more robust applications and greater customer confidence.
Our team of DevSecOps experts can help you secure your APIs, data pipelines, CI/CD chains, Docker containers and Kubernetes deployments.
Discover this offer