VYPR
High severity8.8NVD Advisory· Published Feb 12, 2019· Updated Jun 17, 2026

CVE-2019-5596

CVE-2019-5596

Description

In FreeBSD 11.2-STABLE after r338618 and before r343786, 12.0-STABLE before r343781, and 12.0-RELEASE before 12.0-RELEASE-p3, a bug in the reference count implementation for UNIX domain sockets can cause a file structure to be incorrectly released potentially allowing a malicious local user to gain root privileges or escape from a jail.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • FreeBSD/FreeBSD4 versions
    cpe:2.3:a:freebsd:freebsd:11.2:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:freebsd:freebsd:11.2:*:*:*:*:*:*:*
    • cpe:2.3:a:freebsd:freebsd:12.0:*:*:*:*:*:*:*
    • (no CPE)range: 11.2-STABLE after r338618 and before r343786, 12.0-STABLE before r343781, and 12.0-RELEASE before 12.0-RELEASE-p3
    • (no CPE)range: FreeBSD 12.0 before 12.0-RELEASE-p3

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.