The total size of the user-provided nmreq to nmreq_copyin() was first computed and then trusted during the copyin. This time-of-check to time-of-use bug could lead to kernel memory corruption. On systems configured to include netmap in their devfs_ruleset, a privileged process running in a jail can affect the host environment.
2024-02-15T05:15:08.833
2024-12-09T17:27:41.437
Analyzed
CVSSv3.1: 7.5 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | freebsd | freebsd | < 12.3 | Yes |
Operating System | freebsd | freebsd | 12.3 | Yes |
Operating System | freebsd | freebsd | 12.3 | Yes |
Operating System | freebsd | freebsd | 12.3 | Yes |
Operating System | freebsd | freebsd | 12.3 | Yes |
Operating System | freebsd | freebsd | 12.3 | Yes |
Operating System | freebsd | freebsd | 13.0 | Yes |
Operating System | freebsd | freebsd | 13.0 | Yes |
Operating System | freebsd | freebsd | 13.0 | Yes |
Operating System | freebsd | freebsd | 13.0 | Yes |
Operating System | freebsd | freebsd | 13.0 | Yes |
Operating System | freebsd | freebsd | 13.0 | Yes |
Operating System | freebsd | freebsd | 13.0 | Yes |
Operating System | freebsd | freebsd | 13.0 | Yes |
Operating System | freebsd | freebsd | 13.0 | Yes |
Operating System | freebsd | freebsd | 13.0 | Yes |
Operating System | freebsd | freebsd | 13.0 | Yes |
Operating System | freebsd | freebsd | 13.0 | Yes |
Operating System | freebsd | freebsd | 13.0 | Yes |
Operating System | freebsd | freebsd | 13.0 | Yes |
Operating System | freebsd | freebsd | 13.0 | Yes |
Operating System | freebsd | freebsd | 13.0 | Yes |
Operating System | freebsd | freebsd | 13.0 | Yes |
Operating System | freebsd | freebsd | 13.0 | Yes |
Operating System | freebsd | freebsd | 13.0 | Yes |
Operating System | freebsd | freebsd | 13.0 | Yes |
Operating System | freebsd | freebsd | 13.0 | Yes |
Operating System | freebsd | freebsd | 13.0 | Yes |