CVE-2018-6917: Freebsd
High severity, CVSS 7.5. EPSS: 2% chance of exploitation in the next 30 days.
In FreeBSD before 11.1-STABLE, 11.1-RELEASE-p9, 10.4-STABLE, 10.4-RELEASE-p8 and 10.3-RELEASE-p28, insufficient validation of user-provided font parameters can result in an integer overflow, leading to the use of arbitrary kernel memory as glyph data. Unprivileged users may be able to access privileged kernel data.
Affected products
- Freebsd Freebsd: from 10.0, before 10.4 (fixed in 10.4); from 11.0, before 11.1 (fixed in 11.1)
Published 2018-04-04. Last modified 2026-06-17.