Researchers disclosed three remotely exploitable root-level flaws in FreeBSD's CTL High Availability subsystem, which listens on TCP port 999 by default and accepts any connecting peer without authentication. The bugs affect the CAM Target Layer used for SCSI storage targets, including TrueNAS Enterprise HA clusters and FreeBSD systems configured with kern.cam.ctl.ha_peer, and each issue can independently lead to remote code execution from network access alone through arbitrary kernel read/write, attacker-controlled kernel writes, or a heap overflow in the DATAMOVE path.
The vulnerabilities were reported in March and April, but FreeBSD did not ship a code fix because the HA protocol is designed for fully trusted back-channel networks and embeds raw kernel pointers by design. Instead, maintainers updated the ctl.4 documentation to explicitly warn that exposing the CTL HA network service to untrusted networks effectively grants remote root code execution on the peer node, making strict network isolation of HA traffic the primary mitigation.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
The researchers publicly disclosed three working exploit chains, dubbed FreeBSD-One, FreeBSD-Two, and FreeBSD-Three, showing that each bug in the CTL HA subsystem can independently yield remote root access over TCP port 999. The write-up also documented affected deployments including TrueNAS Enterprise HA clusters and FreeBSD systems with CTL HA enabled.
The researchers reported three remotely exploitable root-level vulnerabilities in FreeBSD's CTL High Availability subsystem to FreeBSD. The content anchors these reports to March and April, but does not provide more specific dates for each report.
FreeBSD chose not to issue a code fix for the CTL HA issues because the protocol trusts its peer by design and embeds raw kernel pointers. Instead, Mark Johnston added a warning to the ctl.4 manpage in commit 3c8f8432 stating that HA must only be used on trusted networks because exposure effectively permits remote code execution on the peer node.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
5 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourceblog.calif.io
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.