High severity7.8NVD Advisory· Published May 25, 2016· Updated May 6, 2026
CVE-2016-1887
CVE-2016-1887
Description
Integer signedness error in the sockargs function in sys/kern/uipc_syscalls.c in FreeBSD 10.1 before p34, 10.2 before p17, and 10.3 before p3 allows local users to cause a denial of service (memory overwrite and kernel panic) or gain privileges via a negative buflen argument, which triggers a heap-based buffer overflow.
Affected products
3Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- cturt.github.io/sendmsg.htmlnvdExploit
- security.freebsd.org/advisories/FreeBSD-SA-16:19.sendmsg.ascnvdVendor Advisory
- www.securitytracker.com/id/1035906nvd
News mentions
0No linked articles in our index yet.