PT-2022-6217 · Freebsd · Freebsd

Lucas Leong

+2

·

Published

2022-02-18

·

Updated

2024-12-09

·

CVE-2022-23085

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FreeBSD (affected versions not specified)
Description The issue is caused by an integer overflow in the nmreq copyin() function of the netmap component. This insufficient bounds checking could lead to kernel memory corruption. On systems configured to include netmap in their devfs ruleset, a privileged process running in a jail can affect the host environment.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Memory Corruption

Integer Overflow

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2023-00490
CVE-2022-23085
ZDI-22-1292

Affected Products

Freebsd