The jail(2) system call has not limited a visiblity of allocated TTYs (the kern.ttys sysctl). This gives rise to an information leak about processes outside the current jail.
Attacker can get information about TTYs allocated on the host or in other jails. Effectively, the information printed by "pstat -t" may be leaked.
References
Link | Resource |
---|---|
https://security.freebsd.org/advisories/FreeBSD-SA-24:02.tty.asc | Vendor Advisory |
https://security.netapp.com/advisory/ntap-20240510-0003/ | Third Party Advisory |
https://security.freebsd.org/advisories/FreeBSD-SA-24:02.tty.asc | Vendor Advisory |
https://security.netapp.com/advisory/ntap-20240510-0003/ | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
04 Jun 2025, 21:55
Type | Values Removed | Values Added |
---|---|---|
CWE | NVD-CWE-noinfo | |
CPE | cpe:2.3:o:freebsd:freebsd:14.0:p4:*:*:*:*:*:* cpe:2.3:o:freebsd:freebsd:13.2:p6:*:*:*:*:*:* cpe:2.3:o:freebsd:freebsd:13.2:p4:*:*:*:*:*:* cpe:2.3:o:freebsd:freebsd:13.2:p3:*:*:*:*:*:* cpe:2.3:o:freebsd:freebsd:*:*:*:*:*:*:*:* cpe:2.3:o:freebsd:freebsd:14.0:p2:*:*:*:*:*:* cpe:2.3:o:freebsd:freebsd:13.2:p9:*:*:*:*:*:* cpe:2.3:o:freebsd:freebsd:14.0:rc3:*:*:*:*:*:* cpe:2.3:o:freebsd:freebsd:13.2:p5:*:*:*:*:*:* cpe:2.3:o:freebsd:freebsd:13.2:p2:*:*:*:*:*:* cpe:2.3:o:freebsd:freebsd:13.2:p1:*:*:*:*:*:* cpe:2.3:o:freebsd:freebsd:14.0:rc4-p1:*:*:*:*:*:* cpe:2.3:o:freebsd:freebsd:13.2:p8:*:*:*:*:*:* cpe:2.3:o:freebsd:freebsd:14.0:p1:*:*:*:*:*:* cpe:2.3:o:freebsd:freebsd:14.0:beta5:*:*:*:*:*:* cpe:2.3:o:freebsd:freebsd:13.2:p7:*:*:*:*:*:* cpe:2.3:o:freebsd:freebsd:14.0:p3:*:*:*:*:*:* |
|
First Time |
Freebsd
Freebsd freebsd |
|
References | () https://security.freebsd.org/advisories/FreeBSD-SA-24:02.tty.asc - Vendor Advisory | |
References | () https://security.netapp.com/advisory/ntap-20240510-0003/ - Third Party Advisory |
21 Nov 2024, 09:01
Type | Values Removed | Values Added |
---|---|---|
References | () https://security.freebsd.org/advisories/FreeBSD-SA-24:02.tty.asc - | |
References | () https://security.netapp.com/advisory/ntap-20240510-0003/ - |
19 Nov 2024, 22:35
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 3.3 |
10 Jun 2024, 19:15
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
References |
|
15 Feb 2024, 05:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-02-15 05:15
Updated : 2025-06-04 21:55
NVD link : CVE-2024-25941
Mitre link : CVE-2024-25941
CVE.ORG link : CVE-2024-25941
JSON object : View
Products Affected
freebsd
- freebsd
CWE