Stack Buffer Overflow in cd9660, tarfs, and ext2fs Filesystems on FreeBSD
CVE-2025-0373
What is CVE-2025-0373?
On 64-bit systems, the VOP_VPTOFH() function in the cd9660, tarfs, and ext2fs file systems contains a stack buffer overflow vulnerability. When an NFS server exports one of these filesystems, a malicious NFS client may trigger a system panic by mounting and accessing the exported filesystem. Although there is a potential risk for greater exploitation, such as evading file permission checks or executing remote kernel code, these scenarios have not been demonstrated. The default configurations of FreeBSD kernels include stack protection, which mitigates some instances of this overflow, potentially preventing severe system disruptions.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
FreeBSD 14.2-RELEASE
FreeBSD 14.1-RELEASE
FreeBSD 13.4-RELEASE
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
