← Back

CVE-2022-23092

nvd nist
Published: Feb 15, 2024Modified: Jun 17, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

The implementation of lib9p's handling of RWALK messages was missing a bounds check needed when unpacking the message contents. The missing check means that the receipt of a specially crafted message will cause lib9p to overwrite unrelated memory. The bug can be triggered by a malicious bhyve guest kernel to overwrite memory in the bhyve(8) process. This could potentially lead to user-mode code execution on the host, subject to bhyve's Capsicum sandbox.

Affected (25)

Products: Freebsd: Freebsd
1 product
Freebsd
Configuration A
25 vulnerable
Vulnerable SoftwareAffected Versions
Freebsd
Version 13.0 beta1
Version 13.0 beta2
Version 13.0 beta3-p1
Version 13.0 beta3
Version 13.0 beta4
Version 13.0 p10
Version 13.0 p11
Version 13.0 p1
Version 13.0 p2
Version 13.0 p3
Version 13.0 p4
Version 13.0 p5
Version 13.0 p6
Version 13.0 p7
Version 13.0 p8
Version 13.0 p9
Version 13.0 rc1
Version 13.0 rc2
Version 13.0 rc3
Version 13.0 rc4
Version 13.0 rc5-p1
Version 13.0 rc5
Version 13.1 b1-p1
Version 13.1 b2-p2
Version 13.1 rc1-p1

References (4)

Source: secteam@freebsd.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.