CVE-2019-5601: Infoleak
In FreeBSD 12.0-STABLE before r347474, 12.0-RELEASE before 12.0-RELEASE-p7, 11.2-STABLE before r347475, and 11.2-RELEASE before 11.2-RELEASE-p11, a bug in the FFS implementation causes up to three bytes of kernel stack memory to be written to disk as uninitialized directory entry padding.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-5601?
CVE-2019-5601 has been classified as a medium severity vulnerability due to its potential to expose uninitialized kernel stack memory.
What versions of FreeBSD are affected by CVE-2019-5601?
CVE-2019-5601 affects FreeBSD versions 11.2 before p11 and 12.0 before p7.
How do I fix CVE-2019-5601?
To fix CVE-2019-5601, upgrade your FreeBSD installation to the latest patched versions, specifically 11.2-RELEASE-p11 or 12.0-RELEASE-p7.
What type of vulnerability is CVE-2019-5601?
CVE-2019-5601 is a vulnerability in the FFS implementation that allows uninitialized directory entry padding to be written to disk.
Is CVE-2019-5601 a remote exploit?
CVE-2019-5601 does not represent a remote exploit, but it can potentially allow local attackers to read sensitive information.