[原文]Race condition in the UFS and EXT2FS file systems in FreeBSD 4.2 and earlier, and possibly other operating systems, makes deleted data available to user processes before it is zeroed out, which allows a local user to access otherwise restricted information.
FreeBSD UFS/EXT2FS File System Arbitrary Data Access Race
Local Access Required
Loss of Confidentiality
FreeBSD contains a flaw that may allow a malicious user to access restricted data which they may not ordinarly have access to. This issue affects the UFS and Ext2FS filesystems. Under certain conditions the filesystem fails to zero deleted blocks before making them available for reuse. It is possible that the flaw may allow disclosure of sensitive data resulting in a loss of confidentiality.
Currently, there are no known workarounds or upgrades to correct this issue. However, FreeBSD has released a patch to address this vulnerability.