CVE-2018-17159

Severity CVSS v4.0:
Pending analysis
Type:
CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
04/12/2018
Last modified:
31/12/2018

Description

In FreeBSD before 11.2-STABLE(r340854) and 11.2-RELEASE-p5, the NFS server lacks a bounds check in the READDIRPLUS NFS request. Unprivileged remote users with access to the NFS server can cause a resource exhaustion by forcing the server to allocate an arbitrarily large memory allocation.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:freebsd:freebsd:*:*:*:*:*:*:*:* 11.2 (excluding)
cpe:2.3:o:freebsd:freebsd:11.2:p5:*:*:*:*:*:*