VYPR
High severity8.8NVD Advisory· Published Mar 9, 2026· Updated Jun 17, 2026

CVE-2025-15547

CVE-2025-15547

Description

By default, jailed processes cannot mount filesystems, including nullfs(4). However, the allow.mount.nullfs option enables mounting nullfs filesystems, subject to privilege checks.

If a privileged user within a jail is able to nullfs-mount directories, a limitation of the kernel's path lookup logic allows that user to escape the jail's chroot, yielding access to the full filesystem of the host or parent jail.

In a jail configured to allow nullfs(4) mounts from within the jail, the jailed root user can escape the jail's filesystem root.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

19
  • FreeBSD/FreeBSD18 versions
    cpe:2.3:o:freebsd:freebsd:13.5:-:*:*:*:*:*:*+ 17 more
    • cpe:2.3:o:freebsd:freebsd:13.5:-:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:13.5:p1:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:13.5:p2:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:13.5:p3:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:13.5:p4:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:13.5:p5:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:13.5:p6:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:13.5:p7:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:13.5:p8:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:14.3:-:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:14.3:p1:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:14.3:p2:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:14.3:p3:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:14.3:p4:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:14.3:p5:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:14.3:p6:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:14.3:p7:*:*:*:*:*:*
    • (no CPE)range: 14.3-RELEASE
  • FreeBSD/jailllm-fuzzy

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.