|
Multiple Vendor KernFS LSEEK Local Kernel Memory Disclosure Vulnerability
The 'kernfs' filesystem in both NetBSD and OpenBSD is prone to a kernel memory disclosure vulnerability. This issue arises due to insufficient sanitization of user-supplied arguments passed to the 'lseek()' system call. An attacker may use information disclosed through this attack to launch other attacks against a computer and potentially to aid in a complete compromise. Note that OpenBSD has completely removed kernfs since OpenBSD 3.8; version 3.7 had kernfs support disabled in their GENERIC kernel, and has never mounted the kernfs filesystem by default. |
|
|
Privacy Statement |