The sendfile system call in FreeBSD 4.8 through 4.11 and 5 through 5.4 can transfer portions of kernel memory if a file is truncated while it is being sent, which could allow remote attackers to obtain sensitive information.
https://www.freebsd.org/security/advisories/FreeBSD-SA-05:02.sendfile.asc