PT-2021-12653 · Freebsd · Freebsd

Published

2020-09-02

·

Updated

2021-04-02

·

CVE-2020-7462

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: FreeBSD versions 11.3-RELEASE before p13 FreeBSD versions 11.4-PRERELEASE before r360733
Description: The issue is caused by improper mbuf handling in the kernel, leading to a use-after-free bug when sending IPv6 Hop-by-Hop options over the loopback interface. This may result in unintended kernel behavior, including a kernel panic.
Recommendations: For FreeBSD versions 11.3-RELEASE before p13, update to p13 or later to resolve the issue. For FreeBSD versions 11.4-PRERELEASE before r360733, update to r360733 or later to resolve the issue. As a temporary workaround, consider restricting the use of IPv6 Hop-by-Hop options over the loopback interface until a patch is available.

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-7462
FREEBSD-SA-20_24

Affected Products

Freebsd