Memory Corruption Vulnerability in MidnightBSD and FreeBSD Kernels
CVE-2020-24863

5.5MEDIUM

Key Information:

Vendor
CVE Published:
3 September 2020

What is CVE-2020-24863?

A memory corruption issue exists in the kern_getfsstat function for MidnightBSD and FreeBSD kernels. This vulnerability can be exploited by an attacker to induce an invalid free, potentially causing the system to crash. The vulnerability arises from handling crafted size values in connection with invalid modes, enabling malicious actors to disrupt system stability. Users are strongly advised to update their systems to mitigate the risks associated with this vulnerability.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.