FreeBSD 7.1 through 8.1-PRERELEASE does not copy the read-only flag when creating a duplicate mbuf buffer reference, which allows local users to cause a denial of service (system file corruption) and gain privileges via the sendfile system call.
FreeBSD could allow a local attacker to gain elevated privileges on the system, caused by improper copying of a read-only flag when a mbuf buffer reference is duplicated. An attacker could exploit this vulnerability using the sendfile() system call to gain elevated privileges on the system.