FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

FreeBSD -- ktrace(2) fails to detach when executing a setuid binary

Affected packages
14.1 <= FreeBSD-kernel < 14.1_3
14.0 <= FreeBSD-kernel < 14.0_9
13.3 <= FreeBSD-kernel < 13.3_5

Details

VuXML ID 8fb61d94-771b-11ef-9a62-002590c1f29c
Discovery 2024-08-07
Entry 2024-09-20

Problem Description:

A logic bug in the code which disables kernel tracing for setuid programs meant that tracing was not disabled when it should have, allowing unprivileged users to trace and inspect the behavior of setuid programs.

Impact:

The bug may be used by an unprivileged user to read the contents of files to which they would not otherwise have access, such as the local password database.

References

CVE Name CVE-2024-6760
FreeBSD Advisory SA-24:06.ktrace