CVE-2013-6832

FreeBSD < 10.0 - Unauthorized Sensitive Information Exposure via nand_ioctl

Title source: llm
STIX 2.1

Description

The nand_ioctl function in sys/dev/nand/nand_geom.c in the nand driver in the kernel in FreeBSD 10 and earlier does not properly initialize a certain data structure, which allows local users to obtain sensitive information from kernel memory via a crafted ioctl call.

References (1)

Core 1
Core References
Exploit, Patch mailing-list x_refsource_fulldisc
http://archives.neohapsis.com/archives/fulldisclosure/2013-11/0106.html

Scores

EPSS 0.0006
EPSS Percentile 17.8%

Details

CWE
CWE-200
Status published
Products (50)
freebsd/freebsd 0.4_1
freebsd/freebsd 1.0
freebsd/freebsd 1.1
freebsd/freebsd 1.1.5
freebsd/freebsd 1.1.5.1
freebsd/freebsd 1.2
freebsd/freebsd 1.5
freebsd/freebsd 2.0
freebsd/freebsd 2.0.1
freebsd/freebsd 2.0.5
... and 40 more
Published Nov 21, 2013
Tracked Since Feb 18, 2026