CVE-2019-15876: Medium severity freebsd kernel vulnerability
In FreeBSD 12.1-STABLE before r356089, 12.1-RELEASE before 12.1-RELEASE-p3, 11.3-STABLE before r356090, and 11.3-RELEASE before 11.3-RELEASE-p7, driver specific ioctl command handlers in the oce network driver failed to check whether the caller has sufficient privileges allowing unprivileged users to send passthrough commands to the device firmware.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-15876?
CVE-2019-15876 has a medium severity rating due to insufficient privilege checks in specific ioctl command handlers within the oce network driver.
How do I fix CVE-2019-15876?
To mitigate CVE-2019-15876, upgrade your FreeBSD installation to version 12.1-RELEASE-p3 or later, or a patched version of 11.3.
What versions of FreeBSD are affected by CVE-2019-15876?
CVE-2019-15876 affects FreeBSD versions 12.1-STABLE prior to r356089, 12.1-RELEASE before 12.1-RELEASE-p3, and 11.3-STABLE prior to r356090.
Who is vulnerable to CVE-2019-15876?
Unprivileged users on affected FreeBSD systems could exploit CVE-2019-15876 to gain unauthorized access through the oce network driver.
What happens if I don't fix CVE-2019-15876?
Failure to address CVE-2019-15876 may allow unprivileged users to execute potentially harmful operations on the affected FreeBSD systems.