CVE-2019-15877: Medium severity freebsd kernel vulnerability
In FreeBSD 12.1-STABLE before r356606 and 12.1-RELEASE before 12.1-RELEASE-p3, driver specific ioctl command handlers in the ixl network driver failed to check whether the caller has sufficient privileges allowing unprivileged users to trigger updates to the device's non-volatile memory.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-15877?
CVE-2019-15877 has been classified as a high severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2019-15877?
To fix CVE-2019-15877, upgrade to FreeBSD 12.1-RELEASE-p3 or later versions.
Which FreeBSD versions are affected by CVE-2019-15877?
CVE-2019-15877 affects FreeBSD 12.1-STABLE prior to r356606 and FreeBSD 12.1-RELEASE before 12.1-RELEASE-p3.
What type of vulnerability is CVE-2019-15877?
CVE-2019-15877 is a privilege escalation vulnerability affecting the ixl network driver.
Can unprivileged users exploit CVE-2019-15877?
Yes, unprivileged users can exploit CVE-2019-15877 to trigger updates to the device's non-volatile memory.