#VU18388 Memory leak in NetBSD
Published: May 3, 2019
Vulnerability identifier: #VU18388
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/U:Clear
CVE-ID: N/A
CWE-ID: CWE-401
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerable software:
NetBSD
NetBSD
Software vendor:
NetBSD Foundation, Inc
NetBSD Foundation, Inc
Description
The vulnerability allows a local user to gain access to sensitive kernel information.
The vulnerability exists due memory leak within the SIOCGIFCONF IOCTL command. A local user can read huge amount of kernel memory, including pointers to bypass KASLR, stack canaries which can be used to exploit stack buffer overflows.
Remediation
Install updates from vendor's website.