In FreeBSD 11.3-STABLE before r350217, 11.3-RELEASE before 11.3-RELEASE-p1, and 11.2-RELEASE before 11.2-RELEASE-p12, due to insufficient initialization of memory copied to userland in the freebsd32_ioctl interface, small amounts of kernel memory may be disclosed to userland processes. This may allow an attacker to leverage this information to obtain elevated privileges either directly or indirectly.
| Software | From | Fixed in |
|---|---|---|
| freebsd / freebsd | 11.2-p3 | 11.2-p3.x |
| freebsd / freebsd | 11.2-p4 | 11.2-p4.x |
| freebsd / freebsd | 11.2-p5 | 11.2-p5.x |
| freebsd / freebsd | 11.2-p7 | 11.2-p7.x |
| freebsd / freebsd | 11.2 | 11.2.x |
| freebsd / freebsd | 11.2-p2 | 11.2-p2.x |
| freebsd / freebsd | 11.2-p6 | 11.2-p6.x |
| freebsd / freebsd | 11.2-p9 | 11.2-p9.x |
| freebsd / freebsd | 11.2-rc3 | 11.2-rc3.x |
| freebsd / freebsd | 11.2-p10 | 11.2-p10.x |
| freebsd / freebsd | 11.0 | 11.0.x |
| freebsd / freebsd | 11.3 | 11.3.x |
| freebsd / freebsd | 11.2-p8 | 11.2-p8.x |
| freebsd / freebsd | 11.2-p11 | 11.2-p11.x |