CVE-2025-0662 – Apache ktrace Uninitialized Information Leak

The following table lists the changes that have been made to the
CVE-2025-0662 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Jan. 30, 2025

    Action Type Old Value New Value
    Added Description In some cases, the ktrace facility will log the contents of kernel structures to userspace. In one such case, ktrace dumps a variable-sized sockaddr to userspace. There, the full sockaddr is copied, even when it is shorter than the full size. This can result in up to 14 uninitialized bytes of kernel memory being copied out to userspace.

    It is possible for an unprivileged userspace program to leak 14 bytes of a kernel heap allocation to userspace.

    Added CWE CWE-122
    Added Reference https://security.freebsd.org/advisories/FreeBSD-SA-25:04.ktrace.asc
Share the Post:

Related Posts