CVE-2017-15037: Freebsd
High severity, CVSS 8.1. EPSS: 1.1% chance of exploitation in the next 30 days.
In FreeBSD through 11.1, the smb_strdupin function in sys/netsmb/smb_subr.c has a race condition with a resultant out-of-bounds read, because it can cause t2p->t_name strings to lack a final '\0' character.
Affected products
- Freebsd Freebsd: up to and including 11.1
Published 2017-10-05. Last modified 2026-06-17.