PT-2023-27333 · Openbsd · Openbsd

·

CVE-2023-40216

·

Published

2023-08-10

·

Updated

2023-08-23

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions OpenBSD versions 7.3 before errata 014
Description The issue is related to a missing argument-count bounds check in console terminal emulation, which could cause incorrect memory access and a kernel crash after receiving crafted DCS or CSI terminal escape sequences.
Recommendations For OpenBSD version 7.3 before errata 014, apply errata 014 to resolve the issue. As a temporary workaround, consider restricting the use of console terminal emulation until the patch is applied.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-40216

Affected Products

Openbsd