CVE-2026-49421: Freebsd
High severity, CVSS 7.1. EPSS: 0.1% chance of exploitation in the next 30 days.
The kernel function that implements unlinkat(2) and funlinkat(2) validated the AT_RESOLVE_BENEATH flag but failed to pass it through to the underlying path lookup. The flag was silently dropped, so path resolution was not actually restricted. A process that uses AT_RESOLVE_BENEATH with unlinkat(2) or funlinkat(2) to confine path resolution can in fact resolve paths above the starting directory. A caller relying on this flag for path containment may delete files outside the intended directory tree.
Affected products
- Freebsd Freebsd: version 14.3 only; version 14.4 only; version 15.0 only; version 15.1 only
Published 2026-08-19. Last modified 2026-09-01.