CVE-2020-25579: Medium severity freebsd kernel vulnerability
In FreeBSD 12.2-STABLE before r368969, 11.4-STABLE before r369047, 12.2-RELEASE before p3, 12.1-RELEASE before p13 and 11.4-RELEASE before p7 msdosfs(5) was failing to zero-fill a pair of padding fields in the dirent structure, resulting in a leak of three uninitialized bytes.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-25579?
CVE-2020-25579 is a vulnerability in FreeBSD that allows for a leak of uninitialized bytes due to a failure to zero-fill padding fields in the dirent structure.
How does CVE-2020-25579 affect FreeBSD?
CVE-2020-25579 affects FreeBSD versions 12.2-STABLE before r368969, 11.4-STABLE before r369047, 12.2-RELEASE before p3, 12.1-RELEASE before p13, and 11.4-RELEASE before p7.
What is the severity of CVE-2020-25579?
The severity of CVE-2020-25579 is medium with a CVSS score of 5.3.
How do I fix CVE-2020-25579?
To fix CVE-2020-25579, users should update their FreeBSD installations to the appropriate patched versions.
Where can I find more information about CVE-2020-25579?
More information about CVE-2020-25579 can be found in the FreeBSD Security Advisory and the NetApp Security Advisory.