CVE-2018-17154

MEDIUM

FreeBSD < 11.2 - Authenticated Denial of Service via freebsd4_getfsstat System Call

Title source: llm
STIX 2.1

Description

In FreeBSD before 11.2-STABLE(r338987), 11.2-RELEASE-p4, and 11.1-RELEASE-p15, due to insufficient memory checking in the freebsd4_getfsstat system call, a NULL pointer dereference can occur. Unprivileged authenticated local users may be able to cause a denial of service.

References (1)

Core 1
Core References

Scores

CVSS v3 5.5
EPSS 0.0004
EPSS Percentile 12.4%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-476
Status published
Products (3)
freebsd/freebsd 11.1 p15
freebsd/freebsd 11.2 p4
freebsd/freebsd < 11.2
Published Sep 28, 2018
Tracked Since Feb 18, 2026