Lucene search

K
cve[email protected]CVE-2022-23086
HistoryFeb 15, 2024 - 5:15 a.m.

CVE-2022-23086

2024-02-1505:15:09
web.nvd.nist.gov
3338
2
cve-2022-23086
handlers
cfg_page
mpr
mps
mpt
privilege escalation
security
nvd

6.8 Medium

AI Score

Confidence

Low

0.0005 Low

EPSS

Percentile

16.4%

Handlers for *_CFG_PAGE read / write ioctls in the mpr, mps, and mpt drivers allocated a buffer of a caller-specified size, but copied to it a fixed size header. Other heap content would be overwritten if the specified size was too small.

Users with access to the mpr, mps or mpt device node may overwrite heap data, potentially resulting in privilege escalation. Note that the device node is only accessible to root and members of the operator group.

CNA Affected

[
  {
    "defaultStatus": "unknown",
    "modules": [
      "mpr",
      "mps",
      "mpt"
    ],
    "product": "FreeBSD",
    "vendor": "FreeBSD",
    "versions": [
      {
        "lessThan": "p1",
        "status": "affected",
        "version": "13.1-RC1",
        "versionType": "release"
      },
      {
        "lessThan": "p11",
        "status": "affected",
        "version": "13.0-RELEASE",
        "versionType": "release"
      },
      {
        "lessThan": "p5",
        "status": "affected",
        "version": "12.3-RELEASE",
        "versionType": "release"
      }
    ]
  }
]

Social References

More

6.8 Medium

AI Score

Confidence

Low

0.0005 Low

EPSS

Percentile

16.4%