CVE-2020-25584: Race Condition
In FreeBSD 13.0-STABLE before n245118, 12.2-STABLE before r369552, 11.4-STABLE before r369560, 13.0-RC5 before p1, 12.2-RELEASE before p6, and 11.4-RELEASE before p9, a superuser inside a FreeBSD jail configured with the non-default allow.mount permission could cause a race condition between the lookup of ".." and remounting a filesystem, allowing access to filesystem hierarchy outside of the jail.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-25584?
CVE-2020-25584 is a vulnerability in FreeBSD that allows a superuser inside a FreeBSD jail with the non-default allow.mount permission to cause a race condition.
What is the severity of CVE-2020-25584?
CVE-2020-25584 has a severity level of 7.5 (High).
Which versions of FreeBSD are affected by CVE-2020-25584?
FreeBSD versions 11.4-RELEASE before p9, 11.4-STABLE before r369560, 12.2-RELEASE before p6, 12.2-STABLE before r369552, and 13.0-STABLE before n245118 are affected by CVE-2020-25584.
How can I fix CVE-2020-25584?
To fix CVE-2020-25584, it is recommended to update to FreeBSD versions that include the relevant patches.
Where can I find more information about CVE-2020-25584?
You can find more information about CVE-2020-25584 in the advisories provided by FreeBSD and NetApp.