PT-2021-12653 · Freebsd · Freebsd
Published
2020-09-02
·
Updated
2021-04-02
·
CVE-2020-7462
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
FreeBSD versions 11.3-RELEASE before p13
FreeBSD versions 11.4-PRERELEASE before r360733
Description:
The issue is caused by improper mbuf handling in the kernel, leading to a use-after-free bug when sending IPv6 Hop-by-Hop options over the loopback interface. This may result in unintended kernel behavior, including a kernel panic.
Recommendations:
For FreeBSD versions 11.3-RELEASE before p13, update to p13 or later to resolve the issue.
For FreeBSD versions 11.4-PRERELEASE before r360733, update to r360733 or later to resolve the issue.
As a temporary workaround, consider restricting the use of IPv6 Hop-by-Hop options over the loopback interface until a patch is available.
Fix
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Freebsd