First published: Tue May 08 2018(Updated: )
In FreeBSD before 11.1-STABLE(r332303), 11.1-RELEASE-p10, 10.4-STABLE(r332321), and 10.4-RELEASE-p9, due to insufficient initialization of memory copied to userland in the Linux subsystem and Atheros wireless driver, small amounts of kernel memory may be disclosed to userland processes. Unprivileged authenticated local users may be able to access small amounts of privileged kernel data.
Credit: secteam@freebsd.org
Affected Software | Affected Version | How to fix |
---|---|---|
FreeBSD Kernel | >=10.0<10.4 | |
FreeBSD Kernel | >=11.0<11.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-6920 is rated as moderate severity due to the potential disclosure of kernel memory to unprivileged userland processes.
To fix CVE-2018-6920, update your FreeBSD system to versions 11.1-STABLE(r332303), 11.1-RELEASE-p10, 10.4-STABLE(r332321), or 10.4-RELEASE-p9 or later.
CVE-2018-6920 affects FreeBSD versions prior to 11.1-STABLE(r332303) and versions before 10.4-RELEASE-p9.
CVE-2018-6920 is considered a local vulnerability since it requires access to userland processes to exploit.
The potential impact of CVE-2018-6920 includes the unauthorized disclosure of kernel memory contents, which could lead to further system compromise.