CVE-2026-45256: Missing permission check in thr_kill2(2)

Published Jun 26, 2026
·
Updated

When used to deliver a signal to a specific thread, thrkill2(2) called pcansignal() to determine whether the operation was permitted but did not check the result before delivering the signal. The signal was sent even when the permission check failed. The system call returned the resulting error to the caller, but by then the signal had already been delivered.

The missing check allows an unprivileged local user who knows or can guess a target's process and thread IDs to send any signal to a process they would not normally be permitted to signal, including processes owned by other users or by root. The same check enforces jail boundaries, so a jailed process can signal processes on the host or in other jails. Thread IDs are allocated globally and sequentially, and so can be discovered by brute force with no visibility into the target.

An attacker can stop or terminate arbitrary processes, including critical system daemons, resulting in a Denial of Service (DoS).

Affected Software

34 affected components
FreeBSD thr_kill2(2)
FreeBSD FreeBSD=14.3
FreeBSD FreeBSD=14.3-p1
FreeBSD FreeBSD=14.3-p10
FreeBSD FreeBSD=14.3-p11
FreeBSD FreeBSD=14.3-p12
FreeBSD FreeBSD=14.3-p13
FreeBSD FreeBSD=14.3-p14
FreeBSD FreeBSD=14.3-p2
FreeBSD FreeBSD=14.3-p3
FreeBSD FreeBSD=14.3-p4
FreeBSD FreeBSD=14.3-p5
FreeBSD FreeBSD=14.3-p6
FreeBSD FreeBSD=14.3-p7
FreeBSD FreeBSD=14.3-p8
FreeBSD FreeBSD=14.3-p9
FreeBSD FreeBSD=14.4
FreeBSD FreeBSD=14.4-p1
FreeBSD FreeBSD=14.4-p2
FreeBSD FreeBSD=14.4-p3
FreeBSD FreeBSD=14.4-p4
FreeBSD FreeBSD=14.4-p5
FreeBSD FreeBSD=14.4-rc1
FreeBSD FreeBSD=15.0
FreeBSD FreeBSD=15.0-p1
FreeBSD FreeBSD=15.0-p2
FreeBSD FreeBSD=15.0-p3
FreeBSD FreeBSD=15.0-p4
FreeBSD FreeBSD=15.0-p5
FreeBSD FreeBSD=15.0-p6
FreeBSD FreeBSD=15.0-p7
FreeBSD FreeBSD=15.0-p8
FreeBSD FreeBSD=15.0-p9
FreeBSD FreeBSD=15.1-rc2

Event History

Jun 26, 2026
CVE Published
via MITRE·02:43 PM
Data Sourced
via MITRE·02:43 PM
DescriptionWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-45256?

CVE-2026-45256 has a medium severity rating of 5.5.

2

How does CVE-2026-45256 affect FreeBSD?

CVE-2026-45256 affects FreeBSD by allowing signals to be sent without proper permission checks, potentially compromising security.

3

What is the potential risk associated with CVE-2026-45256?

The risk associated with CVE-2026-45256 is that unauthorized signals can be sent to threads, which may lead to information exposure or system instability.

4

How do I fix CVE-2026-45256?

To fix CVE-2026-45256, you should apply the recommended patches provided by FreeBSD as outlined in their security advisory.

5

What components of FreeBSD are impacted by CVE-2026-45256?

CVE-2026-45256 specifically impacts the FreeBSD thr_kill2(2) system call.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203