git: 394fb0542a8e - releng/15.0 - vfs: Disallow renameat() with FD_RESOLVE_BENEATH descriptors
- Go to: [ bottom of page ] [ top of archives ] [ this month ]
Date: Tue, 29 Sep 2026 15:59:17 UTC
The branch releng/15.0 has been updated by markj:
URL: https://cgit.FreeBSD.org/src/commit/?id=394fb0542a8e3a15f16388fa3aed3c4045f79325
commit 394fb0542a8e3a15f16388fa3aed3c4045f79325
Author: Mark Johnston <markj@FreeBSD.org>
AuthorDate: 2026-09-28 16:47:56 +0000
Commit: Mark Johnston <markj@FreeBSD.org>
CommitDate: 2026-09-28 18:14:40 +0000
vfs: Disallow renameat() with FD_RESOLVE_BENEATH descriptors
The FD_RESOLVE_BENEATH flag was intended to try to resolve bugzilla PR
262179 without entirely disallowing fd passing between jails. However,
one can use renameat() to bypass the restriction: upon receiving a
directory fd with FD_RESOLVE_BENEATH set, a jailed process can still
move its CWD or one of its ancestors to the directory, and just cd
out of its jail root.
So disallow renameat() when either the source or destination directory
fds has FD_RESOLVE_BENEATH set, like we do with fchdir() and fchroot()
to prevent similar escapes.
Approved by: so
Security: FreeBSD-SA-26:66.jail
Security: CVE-2026-101305
PR: 262179
Reported by: firk@cantconnect.ru
Reviewed by: olce, kib
Differential Revision: https://reviews.freebsd.org/D59875
---
lib/libsys/fcntl.2 | 9 ++++++++-
sys/kern/vfs_syscalls.c | 9 +++++++++
2 files changed, 17 insertions(+), 1 deletion(-)
diff --git a/lib/libsys/fcntl.2 b/lib/libsys/fcntl.2
index d67c38cfbc6c..8777222798d8 100644
--- a/lib/libsys/fcntl.2
+++ b/lib/libsys/fcntl.2
@@ -25,7 +25,7 @@
.\" OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
.\" SUCH DAMAGE.
.\"
-.Dd June 24, 2025
+.Dd September 22, 2026
.Dt FCNTL 2
.Os
.Sh NAME
@@ -173,6 +173,13 @@ and similar operations, and opening a directory with
.Xr openat 2
where the directory descriptor has the flag set causes the new directory
descriptor to also have the flag set.
+A file descriptor with the
+.Dv FD_RESOLVE_BENEATH
+set cannot be used as either the source or target descriptor in
+.Xr renameat 2
+or
+.Xr renameat2 2
+system calls.
.El
.It Dv F_SETFD
Set flags associated with
diff --git a/sys/kern/vfs_syscalls.c b/sys/kern/vfs_syscalls.c
index 8295a6d071e7..3531353e303c 100644
--- a/sys/kern/vfs_syscalls.c
+++ b/sys/kern/vfs_syscalls.c
@@ -3814,6 +3814,15 @@ again:
}
tdvp = tond.ni_dvp;
tvp = tond.ni_vp;
+ if (fvp->v_type == VDIR &&
+ ((fromnd.ni_resflags | tond.ni_resflags) & NIRES_BENEATH) != 0) {
+ /*
+ * We must not rename a directory relative to FD_RESOLVE_BENEATH
+ * descriptors.
+ */
+ error = ENOTCAPABLE;
+ goto out;
+ }
error = vn_start_write(fvp, &mp, V_NOWAIT);
if (error != 0) {
again1: