FreeBSD-SA-21:05.jail_chdirn : jail_attach(2) relies on the caller to change the cwd
Versions Affected : All versions prior to TrueNAS 12.0-U3
Description
When a process, such as jexec(8) or killall(1), calls jail_attach(2) to enter a jail, the jailed root can attach to it using ptrace(2) before the current working directory is changed.
A process with superuser privileges running inside a jail could change the root directory outside of the jail, thereby gaining full read and writing access to all files and directories in the system.
Workaround
No workaround is available, but systems that are not running jails with untrusted root users are not vulnerable.
Mitigation
- Upgrade to TrueNAS 12.0-U3 or later.
Commit
- FreeBSD Revision : r369354
- TrueNAS Commit : ed92d04
- TrueNAS Commit : 42c7377
- JIRA Ticket : NAS-109604