CVE-2020-25583: Critical severity freebsd kernel vulnerability
In FreeBSD 12.2-STABLE before r368250, 11.4-STABLE before r368253, 12.2-RELEASE before p1, 12.1-RELEASE before p11 and 11.4-RELEASE before p5 when processing a DNSSL option, rtsold(8) decodes domain name labels per an encoding specified in RFC 1035 in which the first octet of each label contains the label's length. rtsold(8) did not validate label lengths correctly and could overflow the destination buffer.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-25583?
CVE-2020-25583 is a vulnerability in FreeBSD versions 11.3 to 11.4 and 12.1 to 12.2-RELEASE that allows an attacker to execute arbitrary code or cause a denial of service.
What is the severity of CVE-2020-25583?
The severity of CVE-2020-25583 is critical, with a CVSS score of 9.8.
How does CVE-2020-25583 impact FreeBSD?
CVE-2020-25583 affects FreeBSD versions 11.3 to 11.4 and 12.1 to 12.2-RELEASE, potentially allowing an attacker to execute arbitrary code or cause a denial of service.
How can I fix CVE-2020-25583?
To fix CVE-2020-25583, users should update their FreeBSD installations to the patched versions specified in the FreeBSD security advisory.
Where can I find more information about CVE-2020-25583?
For more information about CVE-2020-25583, you can refer to the FreeBSD security advisory and the NetApp advisory linked in the references.