PT-2024-11519 · Freebsd · Freebsd

Jeff

+1

·

Published

2022-08-09

·

Updated

2025-06-04

·

CVE-2022-23089

CVSS v3.1

4.7

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions No specific software or versions are mentioned in the provided descriptions.
Description The issue arises when dumping core and saving process information, as proc getargv() might return an sbuf with an sbuf len() of 0 or -1, which is not properly handled. This can lead to an out-of-bound read when a user constructs a specially crafted ps string, potentially causing the kernel to crash.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Out of bounds Read

Weakness Enumeration

Related Identifiers

CVE-2022-23089
FREEBSD-SA-22_09

Affected Products

Freebsd