Lucene search

K
freebsdFreeBSD0D3F99F7-B30C-11E9-A87F-A4BADB2F4699
HistoryJul 24, 2019 - 12:00 a.m.

FreeBSD -- File description reference count leak

2019-07-2400:00:00
vuxml.freebsd.org
13

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.0004 Low

EPSS

Percentile

5.1%

Problem Description:
If a process attempts to transmit rights over a UNIX-domain
socket and an error causes the attempt to fail, references
acquired on the rights are not released and are leaked.
This bug can be used to cause the reference counter to wrap
around and free the corresponding file structure.
Impact:
A local user can exploit the bug to gain root privileges
or escape from a jail.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchfreebsd-kernel= 12.0UNKNOWN
FreeBSDanynoarchfreebsd-kernel< 12.0_8UNKNOWN

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.0004 Low

EPSS

Percentile

5.1%

Related for 0D3F99F7-B30C-11E9-A87F-A4BADB2F4699