aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorKyle Evans <kevans@FreeBSD.org>2026-06-25 17:02:47 +0000
committerMark Johnston <markj@FreeBSD.org>2026-06-30 02:32:58 +0000
commitf887a2c04c9ec09c468f6bb0dd510588bf5b1225 (patch)
treed891d894583dc63510325d76e4c1a866438fc913
parent8d086f03b9beebd1caa43549c824b269c8c6bda8 (diff)
kern: fix auditing of ptrace(2) syscall requests
`error` here is the return value of syscall_thread_enter() rather than the syscall itself, so the committed audit records do not reflect reality. This is less harmful than them recording an error when the operation actually succeeded, but it could still possibly be used to throw off IDS techniques with things like bsmtrace. Approved by: so Security: FreeBSD-SA-26:45.audit Security: CVE-2026-49426 Reviewed by: des, kib, markj, csjp Differential Revision: https://reviews.freebsd.org/D57847
-rw-r--r--sys/kern/kern_sig.c2
1 files changed, 1 insertions, 1 deletions
diff --git a/sys/kern/kern_sig.c b/sys/kern/kern_sig.c
index 40da0a79b810..ac1dc00348c1 100644
--- a/sys/kern/kern_sig.c
+++ b/sys/kern/kern_sig.c
@@ -2765,7 +2765,7 @@ ptrace_syscallreq(struct thread *td, struct proc *p,
td->td_errno = nerror;
if (audited)
- AUDIT_SYSCALL_EXIT(error, td);
+ AUDIT_SYSCALL_EXIT(tsr->ts_ret.sr_error, td);
if (!sy_thr_static)
syscall_thread_exit(td, se);
}