Low severity3.3NVD Advisory· Published Feb 15, 2024· Updated Jun 17, 2026
CVE-2024-25941
CVE-2024-25941
Description
The jail(2) system call has not limited a visiblity of allocated TTYs (the kern.ttys sysctl). This gives rise to an information leak about processes outside the current jail.
Attacker can get information about TTYs allocated on the host or in other jails. Effectively, the information printed by "pstat -t" may be leaked.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
19(expand)+ 18 more
- (no CPE)
- (no CPE)range: 14.0-RELEASE
- cpe:2.3:o:freebsd:freebsd:*:*:*:*:*:*:*:*range: <13.2
- cpe:2.3:o:freebsd:freebsd:13.2:p1:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:13.2:p2:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:13.2:p3:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:13.2:p4:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:13.2:p5:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:13.2:p6:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:13.2:p7:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:13.2:p8:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:13.2:p9:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:14.0:beta5:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:14.0:p1:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:14.0:p2:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:14.0:p3:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:14.0:p4:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:14.0:rc3:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:14.0:rc4-p1:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
2- security.freebsd.org/advisories/FreeBSD-SA-24:02.tty.ascnvdVendor Advisory
- security.netapp.com/advisory/ntap-20240510-0003/nvdThird Party Advisory
News mentions
0No linked articles in our index yet.