In FreeBSD 12.1-STABLE before r356911, and 12.1-RELEASE before p5, insufficient checking in the cryptodev module allocated the size of a kernel buffer based on a user-supplied length allowing an unprivileged process to trigger a kernel panic.
| Software | From | Fixed in |
|---|---|---|
| freebsd / freebsd | 12.1-p1 | 12.1-p1.x |
| freebsd / freebsd | 12.1 | 12.1.x |
| freebsd / freebsd | 12.1-p2 | 12.1-p2.x |
| freebsd / freebsd | 12.1-p3 | 12.1-p3.x |
| freebsd / freebsd | 12.1-p4 | 12.1-p4.x |