CVE Database
/

CVE-2019-5609

Back to search

CVE-2019-5609

Published: Aug 29, 2019

Modified: Aug 4, 2024

PUBLISHED

Description

In FreeBSD 12.0-STABLE before r350619, 12.0-RELEASE before 12.0-RELEASE-p9, 11.3-STABLE before r350619, 11.3-RELEASE before 11.3-RELEASE-p2, and 11.2-RELEASE before 11.2-RELEASE-p13, the bhyve e1000 device emulation used a guest-provided value to determine the size of the on-stack buffer without validation when TCP segmentation offload is requested for a transmitted packet. A misbehaving bhyve guest could overwrite memory in the bhyve process on the host.

VendorProductVersions

n/a

FreeBSD

affected
before 12.0-RELEASE-p9
affected
before 11.3-RELEASE-p2
affected
and before 11.2-RELEASE-p13

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now
CVE-2019-5609 - Security Vulnerability | QwikSec