[FREEBSD:521CE804-52FD-11E8-9123-A4BADB2F4699] FreeBSD -- Mishandling of x86 debug exceptions

Severity High
Affected Packages 1
CVEs 1

Problem Description:
The MOV SS and POP SS instructions inhibit debug exceptions
until the instruction boundary following the next instruction.
If that instruction is a system call or similar instruction
that transfers control to the operating system, the debug
exception will be handled in the kernel context instead of
the user context.
Impact:
An authenticated local attacker may be able to read
sensitive data in kernel memory, control low-level operating
system functions, or may panic the system.

Package Affected Version
pkg:freebsd/FreeBSD-kernel < 11.1_10
ID
FREEBSD:521CE804-52FD-11E8-9123-A4BADB2F4699
Severity
high
Severity from
CVE-2018-8897
URL
http://vuxml.freebsd.org/freebsd/521ce804-52fd-11e8-9123-a4badb2f4699.html
Published
2018-05-08T00:00:00
(6 years ago)
Modified
2018-05-08T00:00:00
(6 years ago)
Rights
FreeBSD VuXML Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:freebsd/FreeBSD-kernel FreeBSD-kernel < 11.1_10
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...