Lucene search

K
cvelistFreebsdCVELIST:CVE-2022-23086
HistoryFeb 15, 2024 - 4:57 a.m.

CVE-2022-23086 mpr/mps/mpt driver ioctl heap out-of-bounds write

2024-02-1504:57:19
freebsd
www.cve.org
2
cve-2022-23086
privilege escalation
ioctls
buffer overflow
root access
operator group

7 High

AI Score

Confidence

Low

0.0005 Low

EPSS

Percentile

16.2%

Handlers for *_CFG_PAGE read / write ioctls in the mpr, mps, and mpt drivers allocated a buffer of a caller-specified size, but copied to it a fixed size header. Other heap content would be overwritten if the specified size was too small.

Users with access to the mpr, mps or mpt device node may overwrite heap data, potentially resulting in privilege escalation. Note that the device node is only accessible to root and members of the operator group.

CNA Affected

[
  {
    "defaultStatus": "unknown",
    "modules": [
      "mpr",
      "mps",
      "mpt"
    ],
    "product": "FreeBSD",
    "vendor": "FreeBSD",
    "versions": [
      {
        "lessThan": "p1",
        "status": "affected",
        "version": "13.1-RC1",
        "versionType": "release"
      },
      {
        "lessThan": "p11",
        "status": "affected",
        "version": "13.0-RELEASE",
        "versionType": "release"
      },
      {
        "lessThan": "p5",
        "status": "affected",
        "version": "12.3-RELEASE",
        "versionType": "release"
      }
    ]
  }
]

7 High

AI Score

Confidence

Low

0.0005 Low

EPSS

Percentile

16.2%

Related for CVELIST:CVE-2022-23086