Описание
The qls_eioctl function in sys/dev/qlxge/qls_ioctl.c in the kernel in FreeBSD 10 and earlier does not validate a certain size parameter, which allows local users to obtain sensitive information from kernel memory via a crafted ioctl call.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| kfreebsd-9 | not-affected | package | ||
| kfreebsd-8 | not-affected | package | ||
| kfreebsd-10 | fixed | 10.0~svn258623-1 | package |
EPSS
Процентиль: 18%
0.00057
Низкий
Связанные уязвимости
nvd
около 12 лет назад
The qls_eioctl function in sys/dev/qlxge/qls_ioctl.c in the kernel in FreeBSD 10 and earlier does not validate a certain size parameter, which allows local users to obtain sensitive information from kernel memory via a crafted ioctl call.
github
больше 3 лет назад
The qls_eioctl function in sys/dev/qlxge/qls_ioctl.c in the kernel in FreeBSD 10 and earlier does not validate a certain size parameter, which allows local users to obtain sensitive information from kernel memory via a crafted ioctl call.
EPSS
Процентиль: 18%
0.00057
Низкий