CVE-2019-15880: Buffer Overflow
In FreeBSD 12.1-STABLE before r356911, and 12.1-RELEASE before p5, insufficient checking in the cryptodev module allocated the size of a kernel buffer based on a user-supplied length allowing an unprivileged process to trigger a kernel panic.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-15880?
CVE-2019-15880 is a vulnerability in FreeBSD 12.1-STABLE and 12.1-RELEASE that allows an unprivileged process to trigger a kernel panic.
How severe is CVE-2019-15880?
CVE-2019-15880 has a severity rating of 9.8 (critical).
What is the affected software for CVE-2019-15880?
The affected software for CVE-2019-15880 is FreeBSD 12.1-STABLE before r356911 and 12.1-RELEASE before p5.
How can the vulnerability be fixed?
To fix CVE-2019-15880, it is recommended to update to FreeBSD 12.1-STABLE r356911 or FreeBSD 12.1-RELEASE p5 or later.
Where can I find more information about CVE-2019-15880?
More information about CVE-2019-15880 can be found at the following references: [CVE-2019-15880 - FreeBSD Advisory](https://security.FreeBSD.org/advisories/FreeBSD-SA-20:16.cryptodev.asc) and [CVE-2019-15880 - NetApp Advisory](https://security.netapp.com/advisory/ntap-20200518-0008/).