vulnerability
FreeBSD: VID-31ad2f10-7711-11eb-b87a-901b0ef719ab (CVE-2020-25581): FreeBSD -- jail_remove(2) fails to kill all jailed processes
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 9 | (AV:N/AC:M/Au:S/C:C/I:C/A:C) | Feb 25, 2021 | Feb 25, 2021 | Dec 10, 2025 |
Severity
9
CVSS
(AV:N/AC:M/Au:S/C:C/I:C/A:C)
Published
Feb 25, 2021
Added
Feb 25, 2021
Modified
Dec 10, 2025
Description
Problem Description: Due to a race condition in the jail_remove(2) implementation, it may fail to kill some of the processes. Impact: A process running inside a jail can avoid being killed during jail termination. If a jail is subsequently started with the same root path, a lingering jailed process may be able to exploit the window during which a devfs filesystem is mounted but the jail's devfs ruleset has not been applied, to access device nodes which are ordinarily inaccessible. If the process is privileged, it may be able to escape the jail and gain full access to the system.
Solutions
freebsd-upgrade-base-12_2-release-p4freebsd-upgrade-base-11_4-release-p8
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.