Description
In FreeBSD 12.1-STABLE before r359021, 12.1-RELEASE before 12.1-RELEASE-p3, 11.3-STABLE before r359020, and 11.3-RELEASE before 11.3-RELEASE-p7, a missing null termination check in the jail_set configuration option "osrelease" may return more bytes with a subsequent jail_get system call allowing a malicious jail superuser with permission to create nested jails to read kernel memory.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-28579 | In FreeBSD 12.1-STABLE before r359021, 12.1-RELEASE before 12.1-RELEASE-p3, 11.3-STABLE before r359020, and 11.3-RELEASE before 11.3-RELEASE-p7, a missing null termination check in the jail_set configuration option "osrelease" may return more bytes with a subsequent jail_get system call allowing a malicious jail superuser with permission to create nested jails to read kernel memory. |
References
History
No history.
Status: PUBLISHED
Assigner: freebsd
Published:
Updated: 2024-08-04T09:25:49.043Z
Reserved: 2020-01-21T00:00:00.000Z
Link: CVE-2020-7453
No data.
Status : Modified
Published: 2020-04-29T00:15:12.093
Modified: 2024-11-21T05:37:10.490
Link: CVE-2020-7453
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD