libc stdio buffer overflow
CVE-2023-5941
What is CVE-2023-5941?
In FreeBSD versions 12.4-RELEASE prior to 12.4-RELEASE-p7 and 13.2-RELEASE prior to 13.2-RELEASE-p5, an issue exists in the __sflush() function of the standard I/O library (libc). This function fails to properly update the write space for write-buffered streams when the write(2) system call encounters an error. This flaw can lead to a heap buffer overflow, potentially resulting in data corruption or allowing an attacker to execute arbitrary code at the privilege level of the affected application. Users are advised to apply the necessary patches to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
FreeBSD 12.4-RELEASE
FreeBSD 13.2-RELEASE
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
