CVE-2014-3953: Freebsd

Medium severity, CVSS 4.9. EPSS: 0.4% chance of exploitation in the next 30 days.

FreeBSD 8.4 before p14, 9.1 before p17, 9.2 before p10, and 10.0 before p7 does not properly initialize certain data structures, which allows local users to obtain sensitive information from kernel memory via a (1) SCTP_SNDRCV, (2) SCTP_EXTRCV, or (3) SCTP_RCVINFO SCTP cmsg or a (4) SCTP_PEER_ADDR_CHANGE, (5) SCTP_REMOTE_ERROR, or (6) SCTP_AUTHENTICATION_EVENT notification.

Affected products

  • Freebsd Freebsd: version 8.4 only; version 9.1 only; version 9.2 only; version 10.0 only

Published 2014-07-15. Last modified 2026-06-17.