Permissions, Privileges, and Access Controls in FreeBSD - CVE-2016-1880

 

Permissions, Privileges, and Access Controls in FreeBSD - CVE-2016-1880

Published: February 15, 2017 / Updated: August 8, 2020


Vulnerability identifier: #VU39654
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-1880
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local authenticated user to execute arbitrary code.

The Linux compatibility layer in the kernel in FreeBSD 9.3, 10.1, and 10.2 allows local users to read portions of kernel memory and potentially gain privilege via unspecified vectors, related to "handling of Linux futex robust lists."


Affected software

FreeBSD

How to mitigate CVE-2016-1880

Install update from vendor's website.


External References

Related Security Bulletins