CVE-2019-15874: Input Validation
Published Apr 28, 2020
·Updated
In FreeBSD 12.1-STABLE before r356035, 12.1-RELEASE before 12.1-RELEASE-p4, 11.3-STABLE before r356036, and 11.3-RELEASE before 11.3-RELEASE-p8, incomplete packet data validation may result in memory access after it has been freed leading to a kernel panic or other unpredictable results.
Affected Software
13 affected components
FreeBSD FreeBSD=11.3
FreeBSD FreeBSD=11.3-p1
FreeBSD FreeBSD=11.3-p2
FreeBSD FreeBSD=11.3-p3
FreeBSD FreeBSD=11.3-p4
FreeBSD FreeBSD=11.3-p5
FreeBSD FreeBSD=11.3-p6
FreeBSD FreeBSD=11.3-p7
FreeBSD FreeBSD=12.1
FreeBSD FreeBSD=12.1-p1
FreeBSD FreeBSD=12.1-p2
FreeBSD FreeBSD=12.1-p3
NetApp Clustered Data ONTAP
Remediation
Event History
Apr 28, 2020
CVE Published
via MITRE·11:41 PM
Data Sourced
via MITRE·11:41 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2019-15874?
CVE-2019-15874 refers to incomplete packet data validation in FreeBSD versions before specific releases, leading to potential memory access issues.
2
How severe is CVE-2019-15874?
CVE-2019-15874 has a severity rating of 9.8, classified as critical.
3
What are the affected software versions for CVE-2019-15874?
The affected software versions include FreeBSD 11.3-p1 to 11.3-p7, 12.1-p1 to 12.1-p3, as well as NetApp Clustered Data ONTAP.