Back to search
CVE-2022-23088
Published: Feb 15, 2024
Modified: Apr 24, 2025
PUBLISHED
Description
The 802.11 beacon handling routine failed to validate the length of an IEEE 802.11s Mesh ID before copying it to a heap-allocated buffer. While a FreeBSD Wi-Fi client is in scanning mode (i.e., not associated with a SSID) a malicious beacon frame may overwrite kernel memory, leading to remote code execution.
| Vendor | Product | Versions |
|---|---|---|
FreeBSD | FreeBSD | affected 13.1-RC1 - < p1affected 13.0-RELEASE - < p11affected 12.3-RELEASE - < p5 |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now