#VU36606 NULL pointer dereference in FreeBSD - CVE-2018-17154
Published: September 28, 2018 / Updated: August 8, 2020
FreeBSD
FreeBSD Foundation
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error in FreeBSD before 11.2-STABLE(r338987), 11.2-RELEASE-p4, and 11.1-RELEASE-p15, due to insufficient memory checking in the freebsd4_getfsstat system call, a NULL pointer dereference can occur. Unprivileged authenticated local users may be able to cause a denial of service. A remote attacker can perform a denial of service (DoS) attack.