← Back

CVE-2024-6759

nvd nist
Published: Aug 12, 2024Modified: Jun 17, 2026

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

When mounting a remote filesystem using NFS, the kernel did not sanitize remotely provided filenames for the path separator character, "/". This allows readdir(3) and related functions to return filesystem entries with names containing additional path components. The lack of validation described above gives rise to a confused deputy problem. For example, a program copying files from an NFS mount could be tricked into copying from outside the intended source directory, and/or to a location outside the intended destination directory.

Affected (19)

Products: Freebsd: Freebsd
1 product
Freebsd
Configuration A
19 vulnerable
Vulnerable SoftwareAffected Versions
Freebsd
Before 13.0
From 13.1 to 13.3
Version 13.3 p1
Version 13.3 p2
Version 13.3 p3
Version 13.3 p4
Version 14.0 beta5
Version 14.0 p1
Version 14.0 p2
Version 14.0 p3
Version 14.0 p4
Version 14.0 p5
Version 14.0 p6
Version 14.0 p7
Version 14.0 p8
Version 14.0 rc3
Version 14.0 rc4-p1
Version 14.1 p1
Version 14.1 p2

References (2)

Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.