In FreeBSD 12.0-STABLE before r350619, 12.0-RELEASE before 12.0-RELEASE-p9, 11.3-STABLE before r350619, 11.3-RELEASE before 11.3-RELEASE-p2, and 11.2-RELEASE before 11.2-RELEASE-p13, the bhyve e1000 device emulation used a guest-provided value to determine the size of the on-stack buffer without validation when TCP segmentation offload is requested for a transmitted packet. A misbehaving bhyve guest could overwrite memory in the bhyve process on the host.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: freebsd

Published:

Updated: 2024-08-04T20:01:51.639Z

Reserved: 2019-01-07T00:00:00

Link: CVE-2019-5609

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-08-30T09:15:20.770

Modified: 2024-11-21T04:45:13.797

Link: CVE-2019-5609

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.