CVE-2019-5603: High severity freebsd kernel vulnerability
In FreeBSD 12.0-STABLE before r350261, 12.0-RELEASE before 12.0-RELEASE-p8, 11.3-STABLE before r350263, 11.3-RELEASE before 11.3-RELEASE-p1, and 11.2-RELEASE before 11.2-RELEASE-p12, system calls operating on file descriptors as part of mqueuefs did not properly release the reference allowing a malicious user to overflow the counter allowing access to files, directories, and sockets opened by processes owned by other users.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-5603?
CVE-2019-5603 has been classified as a medium severity vulnerability.
How do I fix CVE-2019-5603?
To fix CVE-2019-5603, upgrade to the patched versions of FreeBSD namely 12.0-RELEASE-p8, 11.3-RELEASE-p1, or 11.2-RELEASE-p12.
What is the impact of CVE-2019-5603?
The impact of CVE-2019-5603 allows an unprivileged user to exploit the vulnerability via incorrect reference counting, potentially leading to a denial of service.
Which versions of FreeBSD are affected by CVE-2019-5603?
FreeBSD versions 11.0, 11.2 through 11.2-RELEASE-p11, 11.3, and 12.0 are affected by CVE-2019-5603.
Is CVE-2019-5603 a remote attack vulnerability?
CVE-2019-5603 does not constitute a remote attack vulnerability, as it requires local access to the affected FreeBSD system.