CVE Database
/

CVE-2022-23084

Back to search

CVE-2022-23084

Published: Feb 15, 2024

Modified: Feb 13, 2025

PUBLISHED

Description

The total size of the user-provided nmreq to nmreq_copyin() was first computed and then trusted during the copyin. This time-of-check to time-of-use bug could lead to kernel memory corruption. On systems configured to include netmap in their devfs_ruleset, a privileged process running in a jail can affect the host environment.

VendorProductVersions

FreeBSD

FreeBSD

affected
13.1-RC1 - < p1
affected
13.0-RELEASE - < p11
affected
12.3-RELEASE - < p5

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now