CVE-2020-7459: Input Validation
In FreeBSD 12.1-STABLE before r362166, 12.1-RELEASE before p8, 11.4-STABLE before r362167, 11.4-RELEASE before p2, and 11.3-RELEASE before p12, missing length validation code common to mulitple USB network drivers allows a malicious USB device to write beyond the end of an allocated network packet buffer.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-7459?
CVE-2020-7459 is a vulnerability in FreeBSD that allows a malicious USB device to write beyond the end of an allocated network packet.
How severe is CVE-2020-7459?
CVE-2020-7459 has a severity score of 6.8, which is considered medium.
Which versions of FreeBSD are affected by CVE-2020-7459?
FreeBSD 12.1-STABLE before r362166, 12.1-RELEASE before p8, 11.4-STABLE before r362167, 11.4-RELEASE before p2, and 11.3-RELEASE before p12 are affected by CVE-2020-7459.
How do I fix CVE-2020-7459?
To fix CVE-2020-7459, update to FreeBSD 12.1-STABLE r362166 or later, 12.1-RELEASE p8 or later, 11.4-STABLE r362167 or later, 11.4-RELEASE p2 or later, or 11.3-RELEASE p12 or later.
Where can I find more information about CVE-2020-7459?
You can find more information about CVE-2020-7459 at the following references: [link1](https://security.FreeBSD.org/advisories/FreeBSD-SA-20:21.usb_net.asc) [link2](https://security.netapp.com/advisory/ntap-20200821-0005/)