Handlers for *_CFG_PAGE read / write ioctls in the mpr, mps, and mpt drivers allocated a buffer of a caller-specified size, but copied to it a fixed size header. Other heap content would be overwritten if the specified size was too small. Users with access to the mpr, mps or mpt device node may overwrite heap data, potentially resulting in privilege escalation. Note that the device node is only accessible to root and members of the operator group.
History

Wed, 28 Aug 2024 21:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-122
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: freebsd

Published: 2024-02-15T04:57:19.622Z

Updated: 2024-08-28T19:55:55.691Z

Reserved: 2022-01-10T22:07:46.040Z

Link: CVE-2022-23086

cve-icon Vulnrichment

Updated: 2024-08-03T03:28:43.508Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-02-15T05:15:09.273

Modified: 2024-08-28T20:35:00.763

Link: CVE-2022-23086

cve-icon Redhat

No data.