Back to search
CVE-2022-23084
Published: Feb 15, 2024
Modified: Feb 13, 2025
PUBLISHED
Description
The total size of the user-provided nmreq to nmreq_copyin() was first computed and then trusted during the copyin. This time-of-check to time-of-use bug could lead to kernel memory corruption. On systems configured to include netmap in their devfs_ruleset, a privileged process running in a jail can affect the host environment.
| Vendor | Product | Versions |
|---|---|---|
FreeBSD | FreeBSD | affected 13.1-RC1 - < p1affected 13.0-RELEASE - < p11affected 12.3-RELEASE - < p5 |
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now