PT-2022-18663 · Openbsd · Openbsd
Francisco Falcon
·
Published
2022-03-25
·
Updated
2022-05-12
·
CVE-2022-27881
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
OpenBSD versions 6.9 through 7.0 before 2022-02-21
Description
The issue is related to a buffer overflow in the
engine.c file of the slaacd component. This overflow can be triggered by an IPv6 router advertisement that contains more than seven nameservers. It is noted that privilege separation and pledge can prevent the exploitation of this issue.Recommendations
For OpenBSD versions 6.9 through 7.0 before 2022-02-21, consider applying privilege separation and pledge to prevent exploitation until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openbsd