#VU18388 Memory leak in NetBSD

 

#VU18388 Memory leak in NetBSD

Published: May 3, 2019


Vulnerability identifier: #VU18388
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/U:Clear
CVE-ID: N/A
CWE-ID: CWE-401
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
NetBSD
Software vendor:
NetBSD Foundation, Inc

Description

The vulnerability allows a local user to gain access to sensitive kernel information.

The vulnerability exists due memory leak within the SIOCGIFCONF IOCTL command. A local user can read huge amount of kernel memory, including pointers to bypass KASLR, stack canaries which can be used to exploit stack buffer overflows.


Remediation

Install updates from vendor's website.

External links