CVE-2026-49421EPSS p2.4%
CVE-2026-49421CVE-2026-49421
freebsd / freebsd
Description
The kernel function that implements unlinkat(2) and funlinkat(2) validated the AT_RESOLVE_BENEATH flag but failed to pass it through to the underlying path lookup. The flag was silently dropped, so path resolution was not actually restricted.
A process that uses AT_RESOLVE_BENEATH with unlinkat(2) or funlinkat(2) to confine path resolution can in fact resolve paths above the starting directory. A caller relying on this flag for path containment may delete files outside the intended directory tree.
Scoring
| CVSS | 7.1 () |
| Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
| EPSS | 0.13% probability of exploitation · percentile 2.4% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-01 |