PT-2025-3998 · Freebsd · Freebsd
Yichen Chai
+1
·
Published
2025-01-29
·
Updated
2025-01-30
·
CVE-2025-0662
CVSS v3.1
4.9
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
FreeBSD (affected versions not specified)
Description
The ktrace facility logs the contents of kernel structures to userspace. In one case, ktrace dumps a variable-sized
sockaddr to userspace, copying the full sockaddr even when it is shorter than the full size. This results in up to 14 uninitialized bytes of kernel memory being copied out to userspace. An unprivileged userspace program can leak 14 bytes of a kernel heap allocation to userspace.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Freebsd