First published: Thu Sep 03 2020(Updated: )
A memory corruption vulnerability was found in the kernel function kern_getfsstat in MidnightBSD before 1.2.7 and 1.3 through 2020-08-19, and FreeBSD through 11.4, that allows an attacker to trigger an invalid free and crash the system via a crafted size value in conjunction with an invalid mode.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Midnightbsd Midnightbsd | <1.2.7 | |
Midnightbsd Midnightbsd | >=1.3<=2020-08-19 | |
FreeBSD FreeBSD | <=11.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-24863 is a memory corruption vulnerability found in the kernel function kern_getfsstat in MidnightBSD and FreeBSD, allowing an attacker to crash the system.
MidnightBSD versions 1.2.7 and earlier, MidnightBSD versions 1.3 through 2020-08-19, and FreeBSD versions up to 11.4 are affected by CVE-2020-24863.
CVE-2020-24863 has a severity score of 5.5, which is considered medium.
An attacker can exploit CVE-2020-24863 by triggering an invalid free and crashing the system using a crafted size value in conjunction with an invalid mode.
You can find more information about CVE-2020-24863 in the following references: [link1], [link2], [link3].