Handlers for *_CFG_PAGE read / write ioctls in the mpr, mps, and mpt drivers allocated a buffer of a caller-specified size, but copied to it a fixed size header. Other heap content would be overwritten if the specified size was too small.
Users with access to the mpr, mps or mpt device node may overwrite heap data, potentially resulting in privilege escalation. Note that the device node is only accessible to root and members of the operator group.
Metrics
Affected Vendors & Products
References
History
Wed, 28 Aug 2024 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-122 | |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: freebsd
Published: 2024-02-15T04:57:19.622Z
Updated: 2024-08-28T19:55:55.691Z
Reserved: 2022-01-10T22:07:46.040Z
Link: CVE-2022-23086
Vulnrichment
Updated: 2024-08-03T03:28:43.508Z
NVD
Status : Awaiting Analysis
Published: 2024-02-15T05:15:09.273
Modified: 2024-08-28T20:35:00.763
Link: CVE-2022-23086
Redhat
No data.