CVE-2022-23086
Published: Feb 15, 2024
Modified: Feb 13, 2025
Description
Handlers for *_CFG_PAGE read / write ioctls in the mpr, mps, and mpt drivers allocated a buffer of a caller-specified size, but copied to it a fixed size header. Other heap content would be overwritten if the specified size was too small. Users with access to the mpr, mps or mpt device node may overwrite heap data, potentially resulting in privilege escalation. Note that the device node is only accessible to root and members of the operator group.
| Vendor | Product | Versions |
|---|---|---|
FreeBSD | FreeBSD | affected 13.1-RC1 - < p1affected 13.0-RELEASE - < p11affected 12.3-RELEASE - < p5 |
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now