Количество 3
Количество 3
CVE-2022-23086
Handlers for *_CFG_PAGE read / write ioctls in the mpr, mps, and mpt drivers allocated a buffer of a caller-specified size, but copied to it a fixed size header. Other heap content would be overwritten if the specified size was too small. Users with access to the mpr, mps or mpt device node may overwrite heap data, potentially resulting in privilege escalation. Note that the device node is only accessible to root and members of the operator group.
GHSA-8xxh-r5gq-2wxg
Handlers for *_CFG_PAGE read / write ioctls in the mpr, mps, and mpt drivers allocated a buffer of a caller-specified size, but copied to it a fixed size header. Other heap content would be overwritten if the specified size was too small. Users with access to the mpr, mps or mpt device node may overwrite heap data, potentially resulting in privilege escalation. Note that the device node is only accessible to root and members of the operator group.
BDU:2023-00050
Уязвимость драйверов mpr, mps, mpt операционных систем FreeBSD, позволяющая нарушителю выполнить произвольный код в системе с повышенными привилегиями
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2022-23086 Handlers for *_CFG_PAGE read / write ioctls in the mpr, mps, and mpt drivers allocated a buffer of a caller-specified size, but copied to it a fixed size header. Other heap content would be overwritten if the specified size was too small. Users with access to the mpr, mps or mpt device node may overwrite heap data, potentially resulting in privilege escalation. Note that the device node is only accessible to root and members of the operator group. | CVSS3: 7.8 | 0% Низкий | почти 2 года назад | |
GHSA-8xxh-r5gq-2wxg Handlers for *_CFG_PAGE read / write ioctls in the mpr, mps, and mpt drivers allocated a buffer of a caller-specified size, but copied to it a fixed size header. Other heap content would be overwritten if the specified size was too small. Users with access to the mpr, mps or mpt device node may overwrite heap data, potentially resulting in privilege escalation. Note that the device node is only accessible to root and members of the operator group. | CVSS3: 9.8 | 0% Низкий | почти 2 года назад | |
BDU:2023-00050 Уязвимость драйверов mpr, mps, mpt операционных систем FreeBSD, позволяющая нарушителю выполнить произвольный код в системе с повышенными привилегиями | CVSS3: 8.2 | 0% Низкий | почти 4 года назад |
Уязвимостей на страницу