Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wq83-w9r6-h456

Опубликовано: 30 апр. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

When processing the header of an incoming message, libnv failed to properly validate the message size.

The lack of validation allows a malicious program to write outside the bounds of a heap allocation. This can trigger a crash or system panic, and it may be possible for an unprivileged user to exploit the bug to elevate their privileges.

When processing the header of an incoming message, libnv failed to properly validate the message size.

The lack of validation allows a malicious program to write outside the bounds of a heap allocation. This can trigger a crash or system panic, and it may be possible for an unprivileged user to exploit the bug to elevate their privileges.

EPSS

Процентиль: 25%
0.00316
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-122

Связанные уязвимости

CVSS3: 8.1
nvd
5 месяцев назад

When processing the header of an incoming message, libnv failed to properly validate the message size. The lack of validation allows a malicious program to write outside the bounds of a heap allocation. This can trigger a crash or system panic, and it may be possible for an unprivileged user to exploit the bug to elevate their privileges.

CVSS3: 8.1
fstec
5 месяцев назад

Уязвимость компонента Message Handler ядра операционных систем FreeBSD, позволяющая нарушителю выполнить произвольный код с привилегиями root

EPSS

Процентиль: 25%
0.00316
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-122