Memory Allocation Vulnerability in FreeBSD's ctl_persistent_reserve_out Function
CVE-2024-39281

5.3MEDIUM

Key Information:

Vendor

FreeBSD

Status
Vendor
CVE Published:
12 November 2024

What is CVE-2024-39281?

A memory allocation vulnerability exists in FreeBSD's ctl_persistent_reserve_out function, where the caller can specify an arbitrary size for the memory allocation request. This flaw could potentially lead to denial of service or other malicious exploitation if not addressed promptly. It poses a significant risk to system stability and security, necessitating vigilant monitoring and timely updates.

Affected Version(s)

FreeBSD 14.1-RELEASE

FreeBSD 13.4-RELEASE

FreeBSD 13.3-RELEASE

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

Credit

Synacktiv
The FreeBSD Foundation
The Alpha-Omega Project
.