#VU35660 Information disclosure in FreeBSD - CVE-2019-5605
Published: July 26, 2019 / Updated: August 8, 2020
FreeBSD
FreeBSD Foundation
Description
The vulnerability allows a remote authenticated user to gain access to sensitive information.
In FreeBSD 11.3-STABLE before r350217, 11.3-RELEASE before 11.3-RELEASE-p1, and 11.2-RELEASE before 11.2-RELEASE-p12, due to insufficient initialization of memory copied to userland in the freebsd32_ioctl interface, small amounts of kernel memory may be disclosed to userland processes. This may allow an attacker to leverage this information to obtain elevated privileges either directly or indirectly.