CVE-2013-6834: Input Validation
The qleioctl function in sys/dev/qlxgbe/qlioctl.c in the kernel in FreeBSD 10 and earlier does not validate a certain size parameter, which allows local users to obtain sensitive information from kernel memory via a crafted ioctl call.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2013-6834?
CVE-2013-6834 is classified as a local information disclosure vulnerability.
How do I fix CVE-2013-6834?
To fix CVE-2013-6834, upgrade to FreeBSD 10.1 or later, or apply the relevant patches provided by FreeBSD.
Who is affected by CVE-2013-6834?
CVE-2013-6834 affects FreeBSD versions 10 and earlier, including multiple specific releases.
What does CVE-2013-6834 exploit?
CVE-2013-6834 exploits a lack of validation in the ql_eioctl function, enabling sensitive information retrieval from kernel memory.
Can CVE-2013-6834 be exploited remotely?
CVE-2013-6834 requires local access to the system, making it primarily a local threat rather than a remote exploit.