CVE-2019-15877: Freebsd

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In FreeBSD 12.1-STABLE before r356606 and 12.1-RELEASE before 12.1-RELEASE-p3, driver specific ioctl command handlers in the ixl network driver failed to check whether the caller has sufficient privileges allowing unprivileged users to trigger updates to the device's non-volatile memory.

Affected products

Published 2020-04-28. Last modified 2026-06-17.