MNBSD-2019-0: Kernel memory disclosure via 32-bit compatibility ioctl handlers

Severity: Unknown

Affected Package: kernel

Summary: Kernel memory disclosure via 32-bit compatibility ioctl handlers

Description

Due to insufficient initialization of memory copied to userland in several 32-bit compatibility ioctl handlers, small amounts of kernel memory may be disclosed to userland processes. A user who can invoke 32-bit FreeBSD ioctls may be able to read small portions of kernel memory, which might contain sensitive information such as file cache or terminal buffer contents.

Affected Versions

kernel

Recommendations

No specific recommendations provided.

References

Additional Information

Aliases: CVE-2019-5605

Published: July 24, 2019
Last Modified: July 24, 2019