#VU27861 Use-after-free in FreeBSD - CVE-2019-15878
Published: May 12, 2020
FreeBSD
FreeBSD Foundation
Description
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to the SCTP layer does improper checking when an application tries to update a shared key. A local user can trigger a use-after-free error by specific sequences of updating shared keys and closing the SCTP association and cause a kernel panic.