CVE Database
/

CVE-2022-23085

Back to search

CVE-2022-23085

Published: Feb 15, 2024

Modified: Feb 13, 2025

PUBLISHED

Description

A user-provided integer option was passed to nmreq_copyin() without checking if it would overflow. This insufficient bounds checking could lead to kernel memory corruption. On systems configured to include netmap in their devfs_ruleset, a privileged process running in a jail can affect the host environment.

VendorProductVersions

FreeBSD

FreeBSD

affected
13.1-RC1 - < p1
affected
13.0-RELEASE - < p11
affected
12.3-RELEASE - < p5

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now