A memory corruption vulnerability was found in the kernel function kern_getfsstat in MidnightBSD before 1.2.7 and 1.3 through 2020-08-19, and FreeBSD through 11.4, that allows an attacker to trigger an invalid free and crash the system via a crafted size value in conjunction with an invalid mode.
2020-09-03T15:15:11.520
2024-11-21T05:16:08.933
Modified
CVSSv3.1: 5.5 (MEDIUM)
AV:L/AC:L/Au:N/C:N/I:N/A:C
3.9
6.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | midnightbsd | midnightbsd | < 1.2.7 | Yes |
Application | midnightbsd | midnightbsd | ≤ 2020-08-19 | Yes |
Operating System | freebsd | freebsd | ≤ 11.4 | Yes |