CVE-2024-25941: Freebsd

Low severity, CVSS 3.3. EPSS: 0.2% chance of exploitation in the next 30 days.

The jail(2) system call has not limited a visiblity of allocated TTYs (the kern.ttys sysctl). This gives rise to an information leak about processes outside the current jail. Attacker can get information about TTYs allocated on the host or in other jails. Effectively, the information printed by "pstat -t" may be leaked.

Affected products

  • Freebsd Freebsd: before 13.2 (fixed in 13.2); version 13.2 only; version 14.0 only

Published 2024-02-15. Last modified 2026-06-17.