CVE detail
CVE-2023-5368 — CVE-2023-5368
Published 2023-10-04 · Modified 2026-06-17 · Vendor freebsd · Product freebsd · Source nvd
MEDIUM
severity
CVSS-derived band
0.0053
EPSS probability
exploitation probability, 30d
42.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
On an msdosfs filesystem, the 'truncate' or 'ftruncate' system calls under certain circumstances populate the additional space in the file with unallocated data from the underlying disk device, rather than zero bytes.
This may permit a user with write access to files on a msdosfs filesystem to read unintended data (e.g. from a previously deleted file).
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References