Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jjwm-g4j5-q96v

Опубликовано: 19 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 5.5

Описание

The compat32 kevent() handler translates a 64-bit kevent struct into a stack- declared 32-bit struct. It did not first zero the stack struct.

An unprivileged user may observe a small amount of uninitialized kernel stack data, which may contain sensitive information.

The compat32 kevent() handler translates a 64-bit kevent struct into a stack- declared 32-bit struct. It did not first zero the stack struct.

An unprivileged user may observe a small amount of uninitialized kernel stack data, which may contain sensitive information.

EPSS

Процентиль: 2%
0.00113
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-908

Связанные уязвимости

CVSS3: 5.5
nvd
около 1 месяца назад

The compat32 kevent() handler translates a 64-bit kevent struct into a stack- declared 32-bit struct. It did not first zero the stack struct. An unprivileged user may observe a small amount of uninitialized kernel stack data, which may contain sensitive information.

CVSS3: 3.3
fstec
6 месяцев назад

Уязвимость подсистемы compat32 ядра операционных систем FreeBSD, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 2%
0.00113
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-908