CVE-2014-3873

low
Published 2014-06-10 · Modified 2026-05-06
CVSS v3
CVSS v2
2.1
VIR risk
2.1

Description

The ktrace utility in the FreeBSD kernel 8.4 before p11, 9.1 before p14, 9.2 before p7, and 9.3-BETA1 before p1 uses an incorrect page fault kernel trace entry size, which allows local users to obtain sensitive information from kernel memory via a kernel process trace.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://www.freebsd.org/security/advisories/FreeBSD-SA-14%3A12.ktrace.asc

OS impact

OSVersionStatusFixed in
freebsd freebsd8.4affected
freebsd freebsd9.1affected
freebsd freebsd9.2affected
freebsd freebsd9.3affected

References

CWEs

CWE-20

Verify integrity in audit chain (admin only). AS-IS.