CVE-2014-0998: Freebsd
High severity, CVSS 7.2. EPSS: 0.9% chance of exploitation in the next 30 days.
Integer signedness error in the vt console driver (formerly Newcons) in FreeBSD 9.3 before p10 and 10.1 before p6 allows local users to cause a denial of service (crash) and possibly gain privileges via a negative value in a VT_WAITACTIVE ioctl call, which triggers an array index error and out-of-bounds kernel memory access.
Affected products
- Freebsd Freebsd: version 10.1 only
Published 2015-02-02. Last modified 2026-06-17.