Versions Affected : All versions prior to TrueNAS 12.0-U3
When a process, such as jexec(8) or killall(1), calls jail_attach(2) to enter a jail, the jailed root can attach to it using ptrace(2) before the current working directory is changed.
A process with superuser privileges running inside a jail could change the root directory outside of the jail, thereby gaining full read and writing access to all files and directories in the system.
No workaround is available, but systems that are not running jails with untrusted root users are not vulnerable.
- Upgrade to TrueNAS 12.0-U3 or later.
- FreeBSD Revision : r369354
- TrueNAS Commit : ed92d04
- TrueNAS Commit : 42c7377
- JIRA Ticket : NAS-109604