Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-23086


Handlers for *_CFG_PAGE read / write ioctls in the mpr, mps, and mpt drivers allocated a buffer of a caller-specified size, but copied to it a fixed size header. Other heap content would be overwritten if the specified size was too small. Users with access to the mpr, mps or mpt device node may overwrite heap data, potentially resulting in privilege escalation. Note that the device node is only accessible to root and members of the operator group.


Published

2024-02-15T05:15:09.273

Last Modified

2024-12-09T23:24:03.727

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 7.8 (HIGH)

Weaknesses
  • Type: Primary
    CWE-787
  • Type: Secondary
    CWE-122

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System freebsd freebsd < 12.3 Yes
Operating System freebsd freebsd 12.3 Yes
Operating System freebsd freebsd 12.3 Yes
Operating System freebsd freebsd 12.3 Yes
Operating System freebsd freebsd 12.3 Yes
Operating System freebsd freebsd 12.3 Yes
Operating System freebsd freebsd 13.0 Yes
Operating System freebsd freebsd 13.0 Yes
Operating System freebsd freebsd 13.0 Yes
Operating System freebsd freebsd 13.0 Yes
Operating System freebsd freebsd 13.0 Yes
Operating System freebsd freebsd 13.0 Yes
Operating System freebsd freebsd 13.0 Yes
Operating System freebsd freebsd 13.0 Yes
Operating System freebsd freebsd 13.0 Yes
Operating System freebsd freebsd 13.0 Yes
Operating System freebsd freebsd 13.0 Yes
Operating System freebsd freebsd 13.0 Yes
Operating System freebsd freebsd 13.0 Yes
Operating System freebsd freebsd 13.0 Yes
Operating System freebsd freebsd 13.0 Yes
Operating System freebsd freebsd 13.0 Yes
Operating System freebsd freebsd 13.0 Yes
Operating System freebsd freebsd 13.0 Yes
Operating System freebsd freebsd 13.0 Yes
Operating System freebsd freebsd 13.0 Yes
Operating System freebsd freebsd 13.0 Yes
Operating System freebsd freebsd 13.0 Yes

References