FreshPorts - VuXML

This page displays vulnerability information about FreeBSD Ports.

The VUXML data was last processed by FreshPorts on 2024-03-28 15:43:32 UTC

List all Vulnerabilities, by package

List all Vulnerabilities, by date

k68

These are the vulnerabilities relating to the commit you have selected:

VuXML IDDescription
253486f5-947d-11ea-92ab-00163e433440FreeBSD -- Improper checking in SCTP-AUTH shared key update

Problem Description:

The SCTP layer does improper checking when an application tries to update a shared key. Therefore an unprivileged local user can trigger a use-after- free situation, for example by specific sequences of updating shared keys and closing the SCTP association.

Impact:

Triggering the use-after-free situation may result in unintended kernel behaviour including a kernel panic.


Discovery 2019-09-19
Entry 2020-05-12
FreeBSD-kernel
ge 11.3 lt 11.3_9

CVE-2019-15878
SA-20:14.sctp