Home / mailingsPDF  

FreeBSD Security Advisory FreeBSD-SA-26:69.udp

Posted on 29 September 2026
FreeBSD security notificat

=============================================================================FreeBSD-SA-26:69.udp Security Advisory
The FreeBSD Project

Topic: IPv6 UDP sendto(2) bypasses jail loopback restriction

Category: core
Module: udp
Announced: 2026-09-29
Credits: Yuxiang Yang, Yizhou Zhao, Ao Wang, Xuewei Feng, Qi Li,
and Ke Xu from Tsinghua University using GLM-5.1 from Z.ai
Affects: All supported versions of FreeBSD.
Corrected: 2026-09-28 15:14:37 UTC (stable/15, 15.1-STABLE)
2026-09-29 16:00:13 UTC (releng/15.1, 15.1-RELEASE-p4)
2026-09-29 15:59:22 UTC (releng/15.0, 15.0-RELEASE-p14)
2026-09-28 16:20:37 UTC (stable/14, 14.5-STABLE)
2026-09-29 16:09:13 UTC (releng/14.5, 14.5-RELEASE-p1)
2026-09-29 15:57:29 UTC (releng/14.4, 14.4-RELEASE-p10)
CVE Name: CVE-2026-101303

For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit <URL:https://security.FreeBSD.org/>.

I. Background

FreeBSD jails provide lightweight operating system virtualization.
Classic (non-VNET) jails share the host kernel's network stack but
restrict the IP addresses that jailed processes may use. When a
jailed process sends traffic to the loopback address, the kernel rewrites
the destination to the jail's primary IP address.

II. Problem Description

The IPv6 UDP send path for unconnected sockets did not apply the jail
policy of rewriting a loopback destination address to the jail's
primary IPv6 address.

III. Impact

A process in a classic (non-VNET) jail can send UDP datagrams to services
listening on the host's IPv6 loopback address, bypassing jail network
isolation.

IV. Workaround

No workaround is available. Systems using only VNET jails, or classic
jails without an IPv6 address, are not affected.

V. Solution

Upgrade your vulnerable system to a supported FreeBSD stable or
release / security branch (releng) dated after the correction date,
and reboot the system.

Perform one of the following:

1) To update your vulnerable system installed from base system packages:

Systems running a 15.0-RELEASE or later version of FreeBSD on the amd64 or
arm64 platforms, which were installed using base system packages, can be
updated via the pkg(8) utility:

# pkg upgrade -r FreeBSD-base
# shutdown -r +10min "Rebooting for a security update"

2) To update your vulnerable system installed from binary distribution sets:

Systems running a RELEASE version of FreeBSD on the amd64 or arm64 platforms
which were not installed using base system packages can be updated via the
freebsd-update(8) utility:

# freebsd-update fetch
# freebsd-update install
# shutdown -r +10min "Rebooting for a security update"

3) To update your vulnerable system via a source code patch:

The following patches have been verified to apply to the applicable
FreeBSD release branches.

a) Download the relevant patch from the location below, and verify the
detached PGP signature using your PGP utility.

# fetch https://security.FreeBSD.org/patches/SA-26:69/udp.patch
# fetch https://security.FreeBSD.org/patches/SA-26:69/udp.patch.asc
# gpg --verify udp.patch.asc

b) Apply the patch. Execute the following commands as root:

# cd /usr/src
# patch -E -p0 < /path/to/patch

c) Recompile your kernel as described in
<URL:https://www.FreeBSD.org/handbook/kernelconfig.html> and reboot the
system.

VI. Correction details

This issue is corrected as of the corresponding Git commit hash in the
following stable and release branches:

Branch/path Hash Revision
- -------------------------------------------------------------------------
stable/15/ f3b4b6b756e2 stable/15-n285663
releng/15.1/ 04aa367f47eb releng/15.1-n283626
releng/15.0/ ae084d5f1d7c releng/15.0-n281125
stable/14/ 809221661a81 stable/14-n275237
releng/14.5/ a62aaafc2659 releng/14.5-n274883
releng/14.4/ ba6c8cdf9826 releng/14.4-n273771
- -------------------------------------------------------------------------

Run the following command to see which files were modified by a
particular commit:

# git show --stat <commit hash>

Or visit the following URL, replacing NNNNNN with the hash:

<URL:https://cgit.freebsd.org/src/commit/?id=NNNNNN>

To determine the commit count in a working tree (for comparison against
nNNNNNN in the table above), run:

# git rev-list --count --first-parent HEAD

VII. References

<URL:https://www.cve.org/CVERecord?id=CVE-2026-101303>

The latest revision of this advisory is available at
<URL:https://security.FreeBSD.org/advisories/FreeBSD-SA-26:69.udp.asc>

 

TOP