VYPR
High severity7.5NVD Advisory· Published Nov 27, 2019· Updated Jun 16, 2026

CVE-2011-2480

CVE-2011-2480

Description

Information Disclosure vulnerability in the 802.11 stack, as used in FreeBSD before 8.2 and NetBSD when using certain non-x86 architectures. A signedness error in the IEEE80211_IOC_CHANINFO ioctl allows a local unprivileged user to cause the kernel to copy large amounts of kernel memory back to the user, disclosing potentially sensitive information.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • FreeBSD/FreeBSD2 versions
    cpe:2.3:o:freebsd:freebsd:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:freebsd:freebsd:*:*:*:*:*:*:*:*range: <8.2
    • (no CPE)range: <8.2
  • NetBSD/NetBSD3 versions
    cpe:2.3:o:netbsd:netbsd:-:*:*:*:*:*:x86:*+ 2 more
    • cpe:2.3:o:netbsd:netbsd:-:*:*:*:*:*:x86:*
    • (no CPE)
    • (no CPE)range: n/a

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.