Memory Sharing Vulnerability in Virtual Memory System
CVE-2022-23091
4MEDIUM
What is CVE-2022-23091?
A vulnerability exists in FreeBSD's virtual memory system due to improper handling of memory sharing, which permits an unprivileged local user process to maintain a mapping of a page after it has been freed. This incorrect management can lead to the unauthorized reading of private information belonging to other processes and potentially the kernel. The issue is reminiscent of previous security advisories but stems from a different root cause. System administrators and cybersecurity professionals must assess their environments to mitigate risks associated with this vulnerability.
Affected Version(s)
FreeBSD 13.1-RELEASE
FreeBSD 13.0-RELEASE
FreeBSD 12.3-RELEASE