The FreeBSD Project issued security advisory FreeBSD-SA-26:10.tty for CVE-2026-5398, a kernel use-after-free flaw in the TIOCNOTTY handler that affects all supported FreeBSD versions. The vulnerability occurs because TIOCNOTTY does not clear a back-pointer from the controlling terminal structure to the calling process session, leaving a dangling pointer after the process exits.
FreeBSD warned that a malicious unprivileged local process could exploit the bug to gain root privileges. The project released fixes across supported stable and release branches on 2026-04-21, said no workaround is available, and directed administrators to apply the updates and reboot affected systems.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
FreeBSD released patches for the vulnerability across supported stable and release branches and stated that no workaround was available. Users were instructed to update their systems and reboot to apply the fix.
The FreeBSD Project published security advisory FreeBSD-SA-26:10.tty for CVE-2026-5398, describing a kernel use-after-free bug in the TIOCNOTTY handler affecting all supported FreeBSD versions. The advisory said an unprivileged local process could exploit the dangling pointer condition to gain root privileges.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.