FreeBSD issued security updates for FreeBSD 14.3 and FreeBSD 13.5 to address multiple vulnerabilities, including a critical jail/chroot escape tracked as CVE-2025-15576. The flaw allows a process to break out of FreeBSD jail isolation by abusing file descriptor (fd) exchange between jails, resulting in loss of filesystem isolation and potential access to the host filesystem; the Canadian Centre for Cyber Security urged administrators to review the advisories and apply updates.
Technical reporting indicates CVE-2025-15576 can be triggered in specific configurations where two sibling jails share a directory via a nullfs mount and can communicate over a Unix domain socket. In that scenario, cooperating processes can exchange directory file descriptors in a way that causes the kernel’s pathname lookup checks to fail to properly enforce the jail root boundary, enabling access to directories outside the jail. No workaround was noted; patching is required. Separately, FreeBSD also addressed CVE-2026-3038, described as a local DoS with possible privilege escalation via routing sockets.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
On February 27, 2026, the Canadian Centre for Cyber Security issued alert AV26-179 highlighting FreeBSD's February 24 advisories and urging users and administrators to review them and install the necessary updates. The alert specifically referenced CVE-2025-15576 and CVE-2026-3038.
As part of the February 24, 2026 advisories, FreeBSD made fixes available for affected binary and source-based installations. Administrators were instructed to apply the updates and reboot, as no workaround was available for CVE-2025-15576.
On February 24, 2026, FreeBSD published security advisories for vulnerabilities affecting FreeBSD 14.3 and 13.5, including the jail/chroot escape flaw CVE-2025-15576 and the routing-socket issue CVE-2026-3038. The jail escape bug can allow filesystem isolation to be broken under specific sibling-jail and nullfs configurations, while the routing-socket flaw can cause local denial of service and may enable privilege escalation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.