Freebsd · Freebsd · CVE-2010-2020
**Name of the Vulnerable Software and Affected Versions**
FreeBSD versions 7.2 through 8.1-PRERELEASE
**Description**
The issue concerns a lack of validation for the length of a certain `fhsize` parameter in the NFS client, specifically in the `sys/nfsclient/nfs vfsops.c` file. This allows local users to gain privileges via a crafted mount request when `vfs.usermount` is enabled.
**Recommendations**
For FreeBSD versions 7.2 through 8.1-PRERELEASE, consider disabling the `vfs.usermount` option to minimize the risk of exploitation until a patch is available.