Missing Null-Termination Character in NVLink Can Lead to Out-of-Buffer Writing
CVE-2024-45288

Currently unrated

Key Information:

Vendor

FreeBSD

Status
Vendor
CVE Published:
5 September 2024

What is CVE-2024-45288?

A missing null-termination character in the last element of an nvlist array string can lead to writing outside the allocated buffer.

Affected Version(s)

FreeBSD 14.1-RELEASE

FreeBSD 14.0-RELEASE

FreeBSD 13.3-RELEASE

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Synacktiv
.