« Back to list

CVE-2019-5603

Status: ModifiedHigh (7.8)—💥 PoC

In FreeBSD 12.0-STABLE before r350261, 12.0-RELEASE before 12.0-RELEASE-p8, 11.3-STABLE before r350263, 11.3-RELEASE before 11.3-RELEASE-p1, and 11.2-RELEASE before 11.2-RELEASE-p12, system calls operating on file descriptors as part of mqueuefs did not properly release the reference allowing a malicious user to overflow the counter allowing access to files, directories, and sockets opened by processes owned by other users.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

💥 Public exploits

Exploit code or detection templates are publicly available. This is not the same as confirmed active exploitation (KEV), but it raises the risk: patch with priority.

⚠️ GitHub proofs of concept are not verified: some are fake or contain malware. Never run them outside an isolated lab.

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2019-5603",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.2,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "secteam@freebsd.org",
      "affectedData": [
        {
          "vendor": "FreeBSD",
          "product": "FreeBSD",
          "versions": [
            {
              "status": "affected",
              "version": "FreeBSD before 12.0-RELEASE-p8"
            },
            {
              "status": "affected",
              "version": "before 11.3-RELEASE-p1"
            },
            {
              "status": "affected",
              "version": "and before 11.2-RELEASE-p12"
            }
          ]
        }
      ]
    }
  ],
  "published": "2019-07-26T01:15:10.737",
  "references": [
    {
      "url": "http://packetstormsecurity.com/files/153752/FreeBSD-Security-Advisory-FreeBSD-SA-19-15.mqueuefs.html",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "secteam@freebsd.org"
    },
    {
      "url": "http://packetstormsecurity.com/files/154172/FreeBSD-Security-Advisory-FreeBSD-SA-19-24.mqueuefs.html",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "secteam@freebsd.org"
    },
    {
      "url": "https://seclists.org/bugtraq/2019/Aug/35",
      "tags": [
        "Broken Link"
      ],
      "source": "secteam@freebsd.org"
    },
    {
      "url": "https://security.FreeBSD.org/advisories/FreeBSD-SA-19:15.mqueuefs.asc",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secteam@freebsd.org"
    },
    {
      "url": "https://security.FreeBSD.org/advisories/FreeBSD-SA-19:24.mqueuefs.asc",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "secteam@freebsd.org"
    },
    {
      "url": "https://security.netapp.com/advisory/ntap-20190814-0003/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "secteam@freebsd.org"
    },
    {
      "url": "http://packetstormsecurity.com/files/153752/FreeBSD-Security-Advisory-FreeBSD-SA-19-15.mqueuefs.html",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://packetstormsecurity.com/files/154172/FreeBSD-Security-Advisory-FreeBSD-SA-19-24.mqueuefs.html",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://seclists.org/bugtraq/2019/Aug/35",
      "tags": [
        "Broken Link"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://security.FreeBSD.org/advisories/FreeBSD-SA-19:15.mqueuefs.asc",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://security.FreeBSD.org/advisories/FreeBSD-SA-19:24.mqueuefs.asc",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://security.netapp.com/advisory/ntap-20190814-0003/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-404"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In FreeBSD 12.0-STABLE before r350261, 12.0-RELEASE before 12.0-RELEASE-p8, 11.3-STABLE before r350263, 11.3-RELEASE before 11.3-RELEASE-p1, and 11.2-RELEASE before 11.2-RELEASE-p12, system calls operating on file descriptors as part of mqueuefs did not properly release the reference allowing a malicious user to overflow the counter allowing access to files, directories, and sockets opened by processes owned by other users."
    },
    {
      "lang": "es",
      "value": "En FreeBSD versión 12.0-STABLE anterior a r350261, versión 12.0-RELEASE anterior a 12.0-RELEASE-p8, versión 11.3-STABLE anterior a r350263, versión 11.3-RELEASE anterior a 11.3-RELEASE-p1, y versión 11.2-RELEASE anterior a 11.2-RELEASE-p12, las llamadas de sistema operando sobre descriptores de archivo como parte de mqueuefs, no liberaron correctamente la referencia, permitiendo a un usuario malicioso desbordar el contador, lo que permite el acceso a archivos, directorios y sockets abiertos por parte de procesos que son propiedad de otros usuarios."
    }
  ],
  "lastModified": "2026-06-17T02:37:55.497",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:11.0:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B4DCF469-DF3A-49F3-9621-F5253893F273"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:11.2:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3ACD1D8D-B3BC-4E99-B846-90A4071DB87B"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:11.2:p10:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0A8A5CDA-E099-47BA-A0C0-2F79C0432156"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:11.2:p11:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9AF6EBB1-EADE-41E2-A47B-0EC20F0C9899"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:11.2:p2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "699FE432-8DF0-49F1-A98B-0E19CE01E5CE"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:11.2:p3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "20B06752-39EE-4600-AC1F-69FB9C88E2A8"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:11.2:p4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "22365F7C-2B00-4B61-84E8-EFBA3B8CFDC0"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:11.2:p5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E86CD544-86C4-4D9D-9CE5-087027509EDA"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:11.2:p6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "64E47AE7-BB45-428E-90E9-38BFDFF23650"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:11.2:p7:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "586B9FA3-65A2-41EB-A848-E4A75565F0CA"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:11.2:p8:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1164B48E-2F28-43C5-9B7B-546EAE12E27D"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:11.2:p9:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F0B15B89-3AD2-4E03-9F47-DA934702187B"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:11.2:rc3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "878DF67E-420A-4229-BEA8-DB9F7161ED9A"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:11.3:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F35957CE-AF9F-40CA-BDD1-FA6A0E73783F"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:12.0:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "826B53C2-517F-4FC6-92E8-E7FCB24F91B4"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:12.0:p1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "93F10A46-AEF2-4FDD-92D6-0CF07B70F986"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:12.0:p2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E1AD57A9-F53A-4E40-966E-F2F50852C5E4"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:12.0:p3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C4029113-130F-4A33-A8A0-BC3E74000378"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:12.0:p4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "46C5A6FD-7BBF-4E84-9895-8EE14DC846E4"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:12.0:p5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6D71D083-3279-4DF4-91E1-38C373DD062F"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:12.0:p6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "882669AB-BCFC-4517-A3E9-33D344F1ED0D"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:12.0:p7:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BC3D24FB-50A2-4E37-A479-AF21F8ECD706"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secteam@freebsd.org"
}