Memory leak in NetBSD - #VU18388

 

Memory leak in NetBSD - #VU18388

Published: May 3, 2019


Vulnerability identifier: #VU18388
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/U:Clear
CVE-ID: N/A
CWE-ID: CWE-401
Exploitation vector: Local access
Exploit availability: No public exploit available
Vendor: NetBSD Foundation, Inc
Affected software:
NetBSD

Detailed vulnerability description

The vulnerability allows a local user to gain access to sensitive kernel information.

The vulnerability exists due memory leak within the SIOCGIFCONF IOCTL command. A local user can read huge amount of kernel memory, including pointers to bypass KASLR, stack canaries which can be used to exploit stack buffer overflows.


Remediation

Install updates from vendor's website.

Sources