-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

=============================================================================
FreeBSD-SA-26:69.udp                                        Security Advisory
                                                          The FreeBSD Project

Topic:          IPv6 UDP sendto(2) bypasses jail loopback restriction

Category:       core
Module:         udp
Announced:      2026-09-29
Credits:        Yuxiang Yang, Yizhou Zhao, Ao Wang, Xuewei Feng, Qi Li,
                and Ke Xu from Tsinghua University using GLM-5.1 from Z.ai
Affects:        All supported versions of FreeBSD.
Corrected:      2026-09-28 15:14:37 UTC (stable/15, 15.1-STABLE)
                2026-09-29 16:00:13 UTC (releng/15.1, 15.1-RELEASE-p4)
                2026-09-29 15:59:22 UTC (releng/15.0, 15.0-RELEASE-p14)
                2026-09-28 16:20:37 UTC (stable/14, 14.5-STABLE)
                2026-09-29 16:09:13 UTC (releng/14.5, 14.5-RELEASE-p1)
                2026-09-29 15:57:29 UTC (releng/14.4, 14.4-RELEASE-p10)
CVE Name:       CVE-2026-101303

For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit <URL:https://security.FreeBSD.org/>.

I.   Background

FreeBSD jails provide lightweight operating system virtualization.
Classic (non-VNET) jails share the host kernel's network stack but
restrict the IP addresses that jailed processes may use.  When a
jailed process sends traffic to the loopback address, the kernel rewrites
the destination to the jail's primary IP address.

II.  Problem Description

The IPv6 UDP send path for unconnected sockets did not apply the jail
policy of rewriting a loopback destination address to the jail's
primary IPv6 address.

III. Impact

A process in a classic (non-VNET) jail can send UDP datagrams to services
listening on the host's IPv6 loopback address, bypassing jail network
isolation.

IV.  Workaround

No workaround is available.  Systems using only VNET jails, or classic
jails without an IPv6 address, are not affected.

V.   Solution

Upgrade your vulnerable system to a supported FreeBSD stable or
release / security branch (releng) dated after the correction date,
and reboot the system.

Perform one of the following:

1) To update your vulnerable system installed from base system packages:

Systems running a 15.0-RELEASE or later version of FreeBSD on the amd64 or
arm64 platforms, which were installed using base system packages, can be
updated via the pkg(8) utility:

# pkg upgrade -r FreeBSD-base
# shutdown -r +10min "Rebooting for a security update"

2) To update your vulnerable system installed from binary distribution sets:

Systems running a RELEASE version of FreeBSD on the amd64 or arm64 platforms
which were not installed using base system packages can be updated via the
freebsd-update(8) utility:

# freebsd-update fetch
# freebsd-update install
# shutdown -r +10min "Rebooting for a security update"

3) To update your vulnerable system via a source code patch:

The following patches have been verified to apply to the applicable
FreeBSD release branches.

a) Download the relevant patch from the location below, and verify the
detached PGP signature using your PGP utility.

# fetch https://security.FreeBSD.org/patches/SA-26:69/udp.patch
# fetch https://security.FreeBSD.org/patches/SA-26:69/udp.patch.asc
# gpg --verify udp.patch.asc

b) Apply the patch.  Execute the following commands as root:

# cd /usr/src
# patch -E -p0 < /path/to/patch

c) Recompile your kernel as described in
<URL:https://www.FreeBSD.org/handbook/kernelconfig.html> and reboot the
system.

VI.  Correction details

This issue is corrected as of the corresponding Git commit hash in the
following stable and release branches:

Branch/path                             Hash                     Revision
- -------------------------------------------------------------------------
stable/15/                              f3b4b6b756e2    stable/15-n285663
releng/15.1/                            04aa367f47eb  releng/15.1-n283626
releng/15.0/                            ae084d5f1d7c  releng/15.0-n281125
stable/14/                              809221661a81    stable/14-n275237
releng/14.5/                            a62aaafc2659  releng/14.5-n274883
releng/14.4/                            ba6c8cdf9826  releng/14.4-n273771
- -------------------------------------------------------------------------

Run the following command to see which files were modified by a
particular commit:

# git show --stat <commit hash>

Or visit the following URL, replacing NNNNNN with the hash:

<URL:https://cgit.freebsd.org/src/commit/?id=NNNNNN>

To determine the commit count in a working tree (for comparison against
nNNNNNN in the table above), run:

# git rev-list --count --first-parent HEAD

VII. References

<URL:https://www.cve.org/CVERecord?id=CVE-2026-101303>

The latest revision of this advisory is available at
<URL:https://security.FreeBSD.org/advisories/FreeBSD-SA-26:69.udp.asc>
-----BEGIN PGP SIGNATURE-----

iQJPBAEBCgA5FiEEthUnfoEIffdcgYM7bljekB8AGu8FAmq8DMIbFIAAAAAABAAO
bWFudTIsMi41KzEuMTIsMCwzAAoJEG5Y3pAfABrvw1MP/2OsryP9G0Y5lwgpfI+b
Oyd7QRpGUoNLRPxq+H35yhkZ1blqSwWdK2NdOKgDxie3onQ3UBiuZu6FI00+7/L6
+RNPBWYNyL6P3JqeMxep/Sq1yjglpduRQ7fcDJbFK48ktvVOtGGUX9txzKOXzZvo
I+yQ0LiRvKgSQdM1WIhuggaGYDliEM9hWj0b5f6DIGkaWpxzUFR3KL0et6LA+asJ
8OkzYp8PGY53fony3eBHRe+8RfXGFsEAlOAU6gEichtEY58SWRLPNNs+iA9mGQ8d
7H+zEzxf4TyKr0xsA3tVZJ9ekEhuNQHO5FSGK0Ad2AhQj/21Zc4IAH4XscvQfQYc
zRLmqAgc/ypfYL0v04OjiuczREwadW5q1wdI7xaLk+mjxY7dKjy2KPhJatGz9yI0
hIwt81J3W6z6Lt5xGbLVxOrXHNIBiDvXTrg+FmkISeTC3xzLSBvv6kwTgdsfpfLx
uWs0x5TZhStB+5K/u8mQXJXXleD2F0Qqt8CchQFqQPU3Yx1GZGMv5vEY6XmbZkmJ
yPsr7lruMGaSpqD/ZdyjfbgDjFEA3cdE7/txTrdOoMYFg9BVHY8lV5V8Vl2SeG+P
0Mc7ZszeOtc2ljMGceiS0rXAB4041oerdbMgnn2rBCAYIhMc4VIrD4a+abbBNqIv
1Fuy+mnQhWuT9suKA0giVl1E
=LoUO
-----END PGP SIGNATURE-----