CVE-2019-15880: Freebsd
Critical severity, CVSS 9.8. EPSS: 1.5% chance of exploitation in the next 30 days.
In FreeBSD 12.1-STABLE before r356911, and 12.1-RELEASE before p5, insufficient checking in the cryptodev module allocated the size of a kernel buffer based on a user-supplied length allowing an unprivileged process to trigger a kernel panic.
Affected products
- Freebsd Freebsd: version 12.1 only
Published 2020-05-13. Last modified 2026-06-17.