FreeBSD-EN-20:19.audit : execve/fexecve system call auditing
Versions Affected : All versions prior to TrueNAS 12.0-U1
Description
All execve/fexecve system calls in affected versions will be reported as a failure, even upon successful execution.
For affected kernels, the exact error reported is EJUSTRETURN, 201, or “Just return” depending on the tooling used. These can safely be considered successful returns for the fexecve and execve system calls. Note that audit trails that were produced by kernels starting with FreeBSD 12.0 will exhibit this problem.
Workaround
No workaround is available.
Mitigation
- Upgrade to TrueNAS 12.0-U1 or later.