CVE-2019-15878: Use After Free
In FreeBSD 12.1-STABLE before r352509, 11.3-STABLE before r352509, and 11.3-RELEASE before p9, an unprivileged local user can trigger a use-after-free situation due to improper checking in SCTP when an application tries to update an SCTP-AUTH shared key.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-15878?
The severity of CVE-2019-15878 is high with a CVSS score of 7.8.
How can an unprivileged local user trigger CVE-2019-15878?
An unprivileged local user can trigger CVE-2019-15878 by exploiting a use-after-free situation in SCTP when updating an SCTP-AUTH shared key.
Which versions of FreeBSD are affected by CVE-2019-15878?
CVE-2019-15878 affects FreeBSD 12.1-STABLE before r352509, 11.3-STABLE before r352509, and 11.3-RELEASE before p9.
How can I fix CVE-2019-15878?
To fix CVE-2019-15878, affected users should update to FreeBSD 11.3-RELEASE p9, 11.3-STABLE r352509, or 12.1-STABLE r352509.
Where can I find more information about CVE-2019-15878?
You can find more information about CVE-2019-15878 on the following websites: https://security.FreeBSD.org/advisories/FreeBSD-SA-20:14.sctp.asc and https://security.netapp.com/advisory/ntap-20200518-0007/