Memory Sharing Vulnerability in Virtual Memory System
CVE-2022-23091

4MEDIUM

Key Information:

Vendor

FreeBSD

Status
Vendor
CVE Published:
15 February 2024

What is CVE-2022-23091?

A vulnerability exists in FreeBSD's virtual memory system due to improper handling of memory sharing, which permits an unprivileged local user process to maintain a mapping of a page after it has been freed. This incorrect management can lead to the unauthorized reading of private information belonging to other processes and potentially the kernel. The issue is reminiscent of previous security advisories but stems from a different root cause. System administrators and cybersecurity professionals must assess their environments to mitigate risks associated with this vulnerability.

Affected Version(s)

FreeBSD 13.1-RELEASE

FreeBSD 13.0-RELEASE

FreeBSD 12.3-RELEASE

References

CVSS V3.1

Score:
4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mark Johnston
.