PT-2026-89875 · Netbsd Foundation · Netbsd
CVSS v3.1
5.5
Média
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
NetBSD contains an information disclosure vulnerability in mm open() within sys/dev/mm.c that allows unprivileged local users to obtain real kernel virtual addresses by opening world-accessible devices such as /dev/null or /dev/zero, which incorrectly receive the PK KMEM process flag. Attackers can exploit this misconfigured flag to bypass the CANSEE KPTR obfuscation mechanism and read kernel virtual addresses for sensitive kernel structures including struct proc, kauth cred, filedesc, and vmspace via sysctl KERN PROC queries.
Correção
Incorrect Permission
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Netbsd