-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 ============================================================================= FreeBSD-SA-26:69.udp Security Advisory The FreeBSD Project Topic: IPv6 UDP sendto(2) bypasses jail loopback restriction Category: core Module: udp Announced: 2026-09-29 Credits: Yuxiang Yang, Yizhou Zhao, Ao Wang, Xuewei Feng, Qi Li, and Ke Xu from Tsinghua University using GLM-5.1 from Z.ai Affects: All supported versions of FreeBSD. Corrected: 2026-09-28 15:14:37 UTC (stable/15, 15.1-STABLE) 2026-09-29 16:00:13 UTC (releng/15.1, 15.1-RELEASE-p4) 2026-09-29 15:59:22 UTC (releng/15.0, 15.0-RELEASE-p14) 2026-09-28 16:20:37 UTC (stable/14, 14.5-STABLE) 2026-09-29 16:09:13 UTC (releng/14.5, 14.5-RELEASE-p1) 2026-09-29 15:57:29 UTC (releng/14.4, 14.4-RELEASE-p10) CVE Name: CVE-2026-101303 For general information regarding FreeBSD Security Advisories, including descriptions of the fields above, security branches, and the following sections, please visit . I. Background FreeBSD jails provide lightweight operating system virtualization. Classic (non-VNET) jails share the host kernel's network stack but restrict the IP addresses that jailed processes may use. When a jailed process sends traffic to the loopback address, the kernel rewrites the destination to the jail's primary IP address. II. Problem Description The IPv6 UDP send path for unconnected sockets did not apply the jail policy of rewriting a loopback destination address to the jail's primary IPv6 address. III. Impact A process in a classic (non-VNET) jail can send UDP datagrams to services listening on the host's IPv6 loopback address, bypassing jail network isolation. IV. Workaround No workaround is available. Systems using only VNET jails, or classic jails without an IPv6 address, are not affected. V. Solution Upgrade your vulnerable system to a supported FreeBSD stable or release / security branch (releng) dated after the correction date, and reboot the system. Perform one of the following: 1) To update your vulnerable system installed from base system packages: Systems running a 15.0-RELEASE or later version of FreeBSD on the amd64 or arm64 platforms, which were installed using base system packages, can be updated via the pkg(8) utility: # pkg upgrade -r FreeBSD-base # shutdown -r +10min "Rebooting for a security update" 2) To update your vulnerable system installed from binary distribution sets: Systems running a RELEASE version of FreeBSD on the amd64 or arm64 platforms which were not installed using base system packages can be updated via the freebsd-update(8) utility: # freebsd-update fetch # freebsd-update install # shutdown -r +10min "Rebooting for a security update" 3) To update your vulnerable system via a source code patch: The following patches have been verified to apply to the applicable FreeBSD release branches. a) Download the relevant patch from the location below, and verify the detached PGP signature using your PGP utility. # fetch https://security.FreeBSD.org/patches/SA-26:69/udp.patch # fetch https://security.FreeBSD.org/patches/SA-26:69/udp.patch.asc # gpg --verify udp.patch.asc b) Apply the patch. Execute the following commands as root: # cd /usr/src # patch -E -p0 < /path/to/patch c) Recompile your kernel as described in and reboot the system. VI. Correction details This issue is corrected as of the corresponding Git commit hash in the following stable and release branches: Branch/path Hash Revision - ------------------------------------------------------------------------- stable/15/ f3b4b6b756e2 stable/15-n285663 releng/15.1/ 04aa367f47eb releng/15.1-n283626 releng/15.0/ ae084d5f1d7c releng/15.0-n281125 stable/14/ 809221661a81 stable/14-n275237 releng/14.5/ a62aaafc2659 releng/14.5-n274883 releng/14.4/ ba6c8cdf9826 releng/14.4-n273771 - ------------------------------------------------------------------------- Run the following command to see which files were modified by a particular commit: # git show --stat Or visit the following URL, replacing NNNNNN with the hash: To determine the commit count in a working tree (for comparison against nNNNNNN in the table above), run: # git rev-list --count --first-parent HEAD VII. References The latest revision of this advisory is available at -----BEGIN PGP SIGNATURE----- iQJPBAEBCgA5FiEEthUnfoEIffdcgYM7bljekB8AGu8FAmq8DMIbFIAAAAAABAAO bWFudTIsMi41KzEuMTIsMCwzAAoJEG5Y3pAfABrvw1MP/2OsryP9G0Y5lwgpfI+b Oyd7QRpGUoNLRPxq+H35yhkZ1blqSwWdK2NdOKgDxie3onQ3UBiuZu6FI00+7/L6 +RNPBWYNyL6P3JqeMxep/Sq1yjglpduRQ7fcDJbFK48ktvVOtGGUX9txzKOXzZvo I+yQ0LiRvKgSQdM1WIhuggaGYDliEM9hWj0b5f6DIGkaWpxzUFR3KL0et6LA+asJ 8OkzYp8PGY53fony3eBHRe+8RfXGFsEAlOAU6gEichtEY58SWRLPNNs+iA9mGQ8d 7H+zEzxf4TyKr0xsA3tVZJ9ekEhuNQHO5FSGK0Ad2AhQj/21Zc4IAH4XscvQfQYc zRLmqAgc/ypfYL0v04OjiuczREwadW5q1wdI7xaLk+mjxY7dKjy2KPhJatGz9yI0 hIwt81J3W6z6Lt5xGbLVxOrXHNIBiDvXTrg+FmkISeTC3xzLSBvv6kwTgdsfpfLx uWs0x5TZhStB+5K/u8mQXJXXleD2F0Qqt8CchQFqQPU3Yx1GZGMv5vEY6XmbZkmJ yPsr7lruMGaSpqD/ZdyjfbgDjFEA3cdE7/txTrdOoMYFg9BVHY8lV5V8Vl2SeG+P 0Mc7ZszeOtc2ljMGceiS0rXAB4041oerdbMgnn2rBCAYIhMc4VIrD4a+abbBNqIv 1Fuy+mnQhWuT9suKA0giVl1E =LoUO -----END PGP SIGNATURE-----