CVE-2019-15880: Freebsd

Critical severity, CVSS 9.8. EPSS: 1.5% chance of exploitation in the next 30 days.

In FreeBSD 12.1-STABLE before r356911, and 12.1-RELEASE before p5, insufficient checking in the cryptodev module allocated the size of a kernel buffer based on a user-supplied length allowing an unprivileged process to trigger a kernel panic.

Affected products

Published 2020-05-13. Last modified 2026-06-17.