CVE Database
/

CVE-2022-23088

Back to search

CVE-2022-23088

Published: Feb 15, 2024

Modified: Apr 24, 2025

PUBLISHED

Description

The 802.11 beacon handling routine failed to validate the length of an IEEE 802.11s Mesh ID before copying it to a heap-allocated buffer. While a FreeBSD Wi-Fi client is in scanning mode (i.e., not associated with a SSID) a malicious beacon frame may overwrite kernel memory, leading to remote code execution.

VendorProductVersions

FreeBSD

FreeBSD

affected
13.1-RC1 - < p1
affected
13.0-RELEASE - < p11
affected
12.3-RELEASE - < p5

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now