-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
=============================================================================
FreeBSD-SA-26:69.udp Security Advisory
The FreeBSD Project
Topic: IPv6 UDP sendto(2) bypasses jail loopback restriction
Category: core
Module: udp
Announced: 2026-09-29
Credits: Yuxiang Yang, Yizhou Zhao, Ao Wang, Xuewei Feng, Qi Li,
and Ke Xu from Tsinghua University using GLM-5.1 from Z.ai
Affects: All supported versions of FreeBSD.
Corrected: 2026-09-28 15:14:37 UTC (stable/15, 15.1-STABLE)
2026-09-29 16:00:13 UTC (releng/15.1, 15.1-RELEASE-p4)
2026-09-29 15:59:22 UTC (releng/15.0, 15.0-RELEASE-p14)
2026-09-28 16:20:37 UTC (stable/14, 14.5-STABLE)
2026-09-29 16:09:13 UTC (releng/14.5, 14.5-RELEASE-p1)
2026-09-29 15:57:29 UTC (releng/14.4, 14.4-RELEASE-p10)
CVE Name: CVE-2026-101303
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit .
I. Background
FreeBSD jails provide lightweight operating system virtualization.
Classic (non-VNET) jails share the host kernel's network stack but
restrict the IP addresses that jailed processes may use. When a
jailed process sends traffic to the loopback address, the kernel rewrites
the destination to the jail's primary IP address.
II. Problem Description
The IPv6 UDP send path for unconnected sockets did not apply the jail
policy of rewriting a loopback destination address to the jail's
primary IPv6 address.
III. Impact
A process in a classic (non-VNET) jail can send UDP datagrams to services
listening on the host's IPv6 loopback address, bypassing jail network
isolation.
IV. Workaround
No workaround is available. Systems using only VNET jails, or classic
jails without an IPv6 address, are not affected.
V. Solution
Upgrade your vulnerable system to a supported FreeBSD stable or
release / security branch (releng) dated after the correction date,
and reboot the system.
Perform one of the following:
1) To update your vulnerable system installed from base system packages:
Systems running a 15.0-RELEASE or later version of FreeBSD on the amd64 or
arm64 platforms, which were installed using base system packages, can be
updated via the pkg(8) utility:
# pkg upgrade -r FreeBSD-base
# shutdown -r +10min "Rebooting for a security update"
2) To update your vulnerable system installed from binary distribution sets:
Systems running a RELEASE version of FreeBSD on the amd64 or arm64 platforms
which were not installed using base system packages can be updated via the
freebsd-update(8) utility:
# freebsd-update fetch
# freebsd-update install
# shutdown -r +10min "Rebooting for a security update"
3) To update your vulnerable system via a source code patch:
The following patches have been verified to apply to the applicable
FreeBSD release branches.
a) Download the relevant patch from the location below, and verify the
detached PGP signature using your PGP utility.
# fetch https://security.FreeBSD.org/patches/SA-26:69/udp.patch
# fetch https://security.FreeBSD.org/patches/SA-26:69/udp.patch.asc
# gpg --verify udp.patch.asc
b) Apply the patch. Execute the following commands as root:
# cd /usr/src
# patch -E -p0 < /path/to/patch
c) Recompile your kernel as described in
and reboot the
system.
VI. Correction details
This issue is corrected as of the corresponding Git commit hash in the
following stable and release branches:
Branch/path Hash Revision
- -------------------------------------------------------------------------
stable/15/ f3b4b6b756e2 stable/15-n285663
releng/15.1/ 04aa367f47eb releng/15.1-n283626
releng/15.0/ ae084d5f1d7c releng/15.0-n281125
stable/14/ 809221661a81 stable/14-n275237
releng/14.5/ a62aaafc2659 releng/14.5-n274883
releng/14.4/ ba6c8cdf9826 releng/14.4-n273771
- -------------------------------------------------------------------------
Run the following command to see which files were modified by a
particular commit:
# git show --stat
Or visit the following URL, replacing NNNNNN with the hash:
To determine the commit count in a working tree (for comparison against
nNNNNNN in the table above), run:
# git rev-list --count --first-parent HEAD
VII. References
The latest revision of this advisory is available at
-----BEGIN PGP SIGNATURE-----
iQJPBAEBCgA5FiEEthUnfoEIffdcgYM7bljekB8AGu8FAmq8DMIbFIAAAAAABAAO
bWFudTIsMi41KzEuMTIsMCwzAAoJEG5Y3pAfABrvw1MP/2OsryP9G0Y5lwgpfI+b
Oyd7QRpGUoNLRPxq+H35yhkZ1blqSwWdK2NdOKgDxie3onQ3UBiuZu6FI00+7/L6
+RNPBWYNyL6P3JqeMxep/Sq1yjglpduRQ7fcDJbFK48ktvVOtGGUX9txzKOXzZvo
I+yQ0LiRvKgSQdM1WIhuggaGYDliEM9hWj0b5f6DIGkaWpxzUFR3KL0et6LA+asJ
8OkzYp8PGY53fony3eBHRe+8RfXGFsEAlOAU6gEichtEY58SWRLPNNs+iA9mGQ8d
7H+zEzxf4TyKr0xsA3tVZJ9ekEhuNQHO5FSGK0Ad2AhQj/21Zc4IAH4XscvQfQYc
zRLmqAgc/ypfYL0v04OjiuczREwadW5q1wdI7xaLk+mjxY7dKjy2KPhJatGz9yI0
hIwt81J3W6z6Lt5xGbLVxOrXHNIBiDvXTrg+FmkISeTC3xzLSBvv6kwTgdsfpfLx
uWs0x5TZhStB+5K/u8mQXJXXleD2F0Qqt8CchQFqQPU3Yx1GZGMv5vEY6XmbZkmJ
yPsr7lruMGaSpqD/ZdyjfbgDjFEA3cdE7/txTrdOoMYFg9BVHY8lV5V8Vl2SeG+P
0Mc7ZszeOtc2ljMGceiS0rXAB4041oerdbMgnn2rBCAYIhMc4VIrD4a+abbBNqIv
1Fuy+mnQhWuT9suKA0giVl1E
=LoUO
-----END PGP SIGNATURE-----