[CVE-2026-58089] When a process calls execve(2) to execute a setuid or setgid

CVE-2026-58089 | CVSS: 7.8 | 严重级别: HIGH

When a process calls execve(2) to execute a setuid or setgid image, hwpmc(4) is supposed to detach PMCs owned by unprivileged processes. An inverted check meant that this scenario was not handled properly.

An unprivileged local user who has attached PMCs to a process can continue monitoring it after the process executes a setuid or setgid binary, contrary to the intended policy.

参考链接:
https://security.freebsd.org/advisories/FreeBSD-SA-26:56.hwpmc.asc

📌 数据来源: NVD 官方

⚠️ 合规声明: 本文内容仅用于网络安全合规学习、科研与授权测试用途。严禁用于任何未授权行为,违者自行承担全部法律责任。
滚动至顶部