integer overflow in packed libnv can lead to buffer allocation issue
CVE-2024-45287

7.5HIGH

Key Information:

Vendor

FreeBSD

Status
Vendor
CVE Published:
5 September 2024

What is CVE-2024-45287?

The vulnerability identified in the packed libnv structure of FreeBSD can lead to an integer overflow resulting from a maliciously crafted value. This flaw can enable attackers to manipulate buffer sizes, causing smaller-than-required buffers to be allocated during data parsing, which may result in potential data loss or corruption. Users of affected versions must review their systems and apply necessary patches to mitigate this risk.

Affected Version(s)

FreeBSD 14.1-RELEASE

FreeBSD 14.0-RELEASE

FreeBSD 13.3-RELEASE

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Synacktiv
Taylor R Campbell (NetBSD)
.