CVE-2013-6834

medium
Published 2013-11-21 ยท Modified 2026-04-29
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
4.9

Description

The ql_eioctl function in sys/dev/qlxgbe/ql_ioctl.c in the kernel in FreeBSD 10 and earlier does not validate a certain size parameter, which allows local users to obtain sensitive information from kernel memory via a crafted ioctl call.

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

OS impact

freebsd FreeBSD Affected 73 releases
VersionStatusFixed in
9.2 Affected โ€”
9.1 Affected โ€”
9.0 Affected โ€”
8.4 Affected โ€”
8.3 Affected โ€”
8.2 Affected โ€”
8.1 Affected โ€”
8.0 Affected โ€”
7.4 Affected โ€”
7.3 Affected โ€”
7.2 Affected โ€”
7.1 Affected โ€”
7.0 Affected โ€”
6.4 Affected โ€”
6.3 Affected โ€”
6.2 Affected โ€”
6.1 Affected โ€”
6.0 Affected โ€”
5.5 Affected โ€”
5.4 Affected โ€”
5.3 Affected โ€”
5.2.1 Affected โ€”
5.2 Affected โ€”
5.1 Affected โ€”
5.0 Affected โ€”
4.9 Affected โ€”
4.8 Affected โ€”
4.7 Affected โ€”
4.6.2 Affected โ€”
4.6 Affected โ€”
4.5 Affected โ€”
4.4 Affected โ€”
4.3 Affected โ€”
4.2 Affected โ€”
4.11 Affected โ€”
4.10 Affected โ€”
4.1.1 Affected โ€”
4.1 Affected โ€”
4.0 Affected โ€”
3.5.1 Affected โ€”
3.5 Affected โ€”
3.4 Affected โ€”
3.3 Affected โ€”
3.2 Affected โ€”
3.1 Affected โ€”
3.0 Affected โ€”
2.2.8 Affected โ€”
2.2.7 Affected โ€”
2.2.6 Affected โ€”
2.2.5 Affected โ€”
2.2.4 Affected โ€”
2.2.3 Affected โ€”
2.2.2 Affected โ€”
2.2.1 Affected โ€”
2.2 Affected โ€”
2.1.7.1 Affected โ€”
2.1.7 Affected โ€”
2.1.6.1 Affected โ€”
2.1.6 Affected โ€”
2.1.5 Affected โ€”
2.1.0 Affected โ€”
2.1 Affected โ€”
2.0.5 Affected โ€”
2.0.1 Affected โ€”
2.0 Affected โ€”
1.5 Affected โ€”
1.2 Affected โ€”
1.1.5.1 Affected โ€”
1.1.5 Affected โ€”
1.1 Affected โ€”
1.0 Affected โ€”
0.4_1 Affected โ€”
โ€” Affected โ€”

References

CWEs

CWE-20

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.