← Back

CVE-2018-17155

nvd nist
Published: Sep 28, 2018Modified: Nov 21, 2024

JSON object

Loading...
5.5
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 1.8 / Impact: 3.6
Source: NVD

Description

In FreeBSD before 11.2-STABLE(r338983), 11.2-RELEASE-p4, 11.1-RELEASE-p15, 10.4-STABLE(r338984), and 10.4-RELEASE-p13, due to insufficient initialization of memory copied to userland in the getcontext and swapcontext system calls, small amounts of kernel memory may be disclosed to userland processes. Unprivileged authenticated local users may be able to access small amounts privileged kernel data.

Affected (5)

Products: Freebsd: Freebsd
1 product
Freebsd
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Freebsd
Before 11.2
Version 10.4
Version 10.4 p13
Version 11.1 p15
Version 11.2 p4

References (2)

Source: secteam@freebsd.org
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.