aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorKyle Evans <kevans@FreeBSD.org>2026-06-25 17:02:47 +0000
committerMark Johnston <markj@FreeBSD.org>2026-06-30 17:00:27 +0000
commitec19899607813702d94b13798a9ed78dffdce719 (patch)
tree368e952690c184a104d0a2da40063b897db917d0
parent702f4c829c171b9d63f23e0d6753c80572315bc3 (diff)
kern: fix auditing of ptrace(2) syscall requests
`error` here is the return value of syscall_thread_enter() rather than the syscall itself, so the committed audit records do not reflect reality. This is less harmful than them recording an error when the operation actually succeeded, but it could still possibly be used to throw off IDS techniques with things like bsmtrace. Approved by: so Security: FreeBSD-SA-26:45.audit Security: CVE-2026-49426 Reviewed by: des, kib, markj, csjp Differential Revision: https://reviews.freebsd.org/D57847
-rw-r--r--sys/kern/kern_sig.c2
1 files changed, 1 insertions, 1 deletions
diff --git a/sys/kern/kern_sig.c b/sys/kern/kern_sig.c
index e48997ed966a..fed5b62ee1c7 100644
--- a/sys/kern/kern_sig.c
+++ b/sys/kern/kern_sig.c
@@ -2766,7 +2766,7 @@ ptrace_syscallreq(struct thread *td, struct proc *p,
td->td_errno = nerror;
if (audited)
- AUDIT_SYSCALL_EXIT(error, td);
+ AUDIT_SYSCALL_EXIT(tsr->ts_ret.sr_error, td);
if (!sy_thr_static)
syscall_thread_exit(td, se);
}