Six vulnerabilities have been fixed in FreeBSD, which allow privilege escalation or access to kernel data. The issues have been addressed in the updates 12.0-RELEASE-p8, 11.2-RELEASE-p12, and 11.3-RELEASE-p1.
- — A bug in the close call handler for file descriptors created through the posix_openpt system call may lead to writes to already freed areas of kernel memory (write-after-free). A local attacker can exploit the vulnerability to gain root privileges or escape from the jail environment;
- — Insufficient validation of values when processing environment variables in the telnet client code may lead to a buffer overflow when connecting to a malicious server and perform a client-side code execution attack;
- — A bug in the implementation of freebsd32_ioctl may lead to a leak of kernel memory areas that may potentially contain residual data from terminal buffers or file caches;
- — The potential to initiate a counter overflow in the pseudo-FS mqueuefs, which can be used to gain access to files, directories, and sockets of other processes owned by other users. This issue can also be exploited to escape from jail and, if root access is available within the jail, to gain root privileges in the main system;
- — A bug in value checks for the 'epid' and 'streamid' parameters in the XHCI device emulation code in the bhyve hypervisor allows determining memory values beyond the allocated buffer or initiating a system crash;
- — A leak of reference counters on UNIX socket descriptors used for privilege transmission between processes can be exploited to gain root access or escape from the jail environment.
Source : opennet.ru
