EchelonGraph verdictPlan mitigationSerious severity, but no confirmed exploitation yet.
- •High severity, but no confirmed exploitation yet
CISA-KEV: Not listedEPSS PROB: 0.5%CVSS: 8.8Exploit: None knownExposed services: Not assessed
No fix is confirmed yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for the fix.
When the JAIL_AT_DESC flag is specified, kern_jail_set() and kern_jail_get() released the reference to the caller's current prison before looking up the jail descriptor. If the descriptor lookup failed, error-handling paths released the same reference a second time.
An unprivileged local user can trigger a prison reference count underflow, which may cause the prison structure to be freed while still in use. When this is done on the jail host, the bug will generally result in an immediate panic. However, if the user is running in a jail, then it may be possible to exploit the bug to elevate privileges.
CISA SSVCTrack at low or medium mission impact; Track* at high (mission-essential systems).
No fix is confirmed yet. Restrict network exposure of the affected system or apply the vendor's mitigation within your standard update timelines, and watch the vendor's advisory for the fix.
Exploitation none (CISA Vulnrichment) · Automatable no (CISA Vulnrichment) · Technical impact total (CISA Vulnrichment). Mission impact is CISA's Mission & Well-being decision point, and only you can judge it: high means the affected system is essential to your organisation's mission, or its compromise could cause irreversible harm to people. CISA's decision table