VYPR
Unrated severityNVD Advisory· Published Jul 15, 2014· Updated May 6, 2026

CVE-2014-3953

CVE-2014-3953

Description

FreeBSD kernel memory disclosure via uninitialized padding in SCTP control messages and notifications.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

FreeBSD kernel memory disclosure via uninitialized padding in SCTP control messages and notifications.

Vulnerability

CVE-2014-3953 affects FreeBSD 8.4 before p14, 9.1 before p17, 9.2 before p10, and 10.0 before p7. The kernel does not properly initialize padding in certain SCTP control messages (SCTP_SNDRCV, SCTP_EXTRCV, SCTP_RCVINFO) and notifications (SCTP_PEER_ADDR_CHANGE, SCTP_REMOTE_ERROR, SCTP_AUTHENTICATION_EVENT), leading to disclosure of uninitialized kernel memory [1].

Exploitation

A local attacker can invoke the affected recvmsg(2) or sendmsg(2) system calls using the specific SCTP message types listed above. No special privileges beyond local user access are required; the attacker simply needs to craft appropriate socket operations that trigger the copying of the control message or notification to user space, where the uninitialized padding bytes from kernel heap/stack are exposed [1].

Impact

Successful exploitation results in a kernel memory disclosure leak of potentially sensitive information (e.g., cryptographic keys, passwords, or other secrets) from kernel memory to an unprivileged local user. This violates confidentiality without requiring any privilege escalation [1].

Mitigation

The issue was corrected in FreeBSD stable/10 (10.0-STABLE) and releng/10.0 (10.0-RELEASE-p7) on 2014-07-08, as well as in stable/9, releng/9.3, releng/9.2, releng/9.1, stable/8, and releng/8.4 (respective patch levels) on the same date [1]. Administrators should update to the patched versions. No workaround is documented, and there is no indication of this CVE being listed on CISA's Known Exploited Vulnerabilities catalog.

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

5
  • FreeBSD/FreeBSD5 versions
    cpe:2.3:o:freebsd:freebsd:10.0:*:*:*:*:*:*:*+ 4 more
    • cpe:2.3:o:freebsd:freebsd:10.0:*:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:8.4:*:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:9.1:*:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:9.2:-:*:*:*:*:*:*
    • (no CPE)range: <=8.4p13, <=9.1p16, <=9.2p9, <=10.0p6

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.