CVE-2020-7460: FreeBSD Kernel sendmsg System Call Time-Of-Check Time-Of-Use Privilege Escalation Vulnerability
In FreeBSD 12.1-STABLE before r363918, 12.1-RELEASE before p8, 11.4-STABLE before r363919, 11.4-RELEASE before p2, and 11.3-RELEASE before p12, the sendmsg system call in the compat32 subsystem on 64-bit platforms has a time-of-check to time-of-use vulnerability allowing a mailcious userspace program to modify control message headers after they were validation.
Other sources
This vulnerability allows local attackers to escalate privileges on affected installations of FreeBSD Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of arguments to the sendmsg system call. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this vulnerability to escalate privileges and execute code in the context of the kernel.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-7460?
CVE-2020-7460 is a privilege escalation vulnerability in the FreeBSD Kernel.
How does CVE-2020-7460 impact FreeBSD Kernel?
CVE-2020-7460 allows local attackers to escalate privileges on affected installations of FreeBSD Kernel.
What is the severity of CVE-2020-7460?
CVE-2020-7460 has a severity score of 8.8 (high).
How can CVE-2020-7460 be fixed?
To fix CVE-2020-7460, users should apply the necessary patches or updates provided by FreeBSD.
Where can I find more information about CVE-2020-7460?
You can find more information about CVE-2020-7460 at the following sources: FreeBSD Security Advisories, NetApp Security Advisory, and Zero Day Initiative Advisories.