7.8
CVSSv2

CVE-2019-5612

Published: 30/08/2019 Updated: 31/01/2023
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

In FreeBSD 12.0-STABLE before r351264, 12.0-RELEASE prior to 12.0-RELEASE-p10, 11.3-STABLE before r351265, 11.3-RELEASE prior to 11.3-RELEASE-p3, and 11.2-RELEASE prior to 11.2-RELEASE-p14, the kernel driver for /dev/midistat implements a read handler that is not thread-safe. A multi-threaded program can exploit races in the handler to copy out kernel memory outside the boundaries of midistat's data buffer.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

freebsd freebsd 11.2

freebsd freebsd 12.0

freebsd freebsd 11.3

netapp clustered data ontap -