FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

FreeBSD -- Improper checking in SCTP-AUTH shared key update

Affected packages
11.3 <= FreeBSD-kernel < 11.3_9

Details

VuXML ID 253486f5-947d-11ea-92ab-00163e433440
Discovery 2019-09-19
Entry 2020-05-12

Problem Description:

The SCTP layer does improper checking when an application tries to update a shared key. Therefore an unprivileged local user can trigger a use-after- free situation, for example by specific sequences of updating shared keys and closing the SCTP association.

Impact:

Triggering the use-after-free situation may result in unintended kernel behaviour including a kernel panic.

References

CVE Name CVE-2019-15878
FreeBSD Advisory SA-20:14.sctp