#VU26239 Resource management error in FreeBSD - CVE-2020-7453
Published: March 19, 2020
FreeBSD
FreeBSD Foundation
Description
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to a missing NUL-termination check for the jail_set(2) configration option "osrelease" that leads disclosure of additional bytes of kernel memory than was originally set. A local privileges user inside a non-default jail, e.g. setting of children.max > 0 ("nested jails"), can read exposed kernel memory.