- Sun 27 September 2026
- FreeBSD
My Ansible Plugin Had a Jail Escape: CVE-2026-55074
For almost a year, my jailexec connection plugin let a compromised FreeBSD jail redirect a root-owned write onto the jail host. The input validation was fine. The problem was on which side of the jail boundary the paths were resolved. This is the story of the bug, the fix in 2.0.0, and the CVE that came with it.