CVE-2020-7464: Medium severity freebsd kernel vulnerability
In FreeBSD 12.2-STABLE before r365730, 11.4-STABLE before r365738, 12.1-RELEASE before p10, 11.4-RELEASE before p4, and 11.3-RELEASE before p14, a programming error in the ure(4) device driver caused some Realtek USB Ethernet interfaces to incorrectly report packets with more than 2048 bytes in a single USB transfer as having a length of only 2048 bytes. An adversary can exploit this to cause the driver to misinterpret part of the payload of a large packet as a separate packet, and thereby inject packets across security boundaries such as VLANs.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this FreeBSD vulnerability?
The vulnerability ID for this FreeBSD vulnerability is CVE-2020-7464.
What is the severity of CVE-2020-7464?
The severity of CVE-2020-7464 is medium.
What software versions are affected by CVE-2020-7464?
FreeBSD versions 11.3, 11.4, 12.1, and 12.2 are affected by CVE-2020-7464.
How can I fix CVE-2020-7464?
To fix CVE-2020-7464, users should update to FreeBSD 12.2-STABLE r365730, 11.4-STABLE r365738, 12.1-RELEASE p10, 11.4-RELEASE p4, or 11.3-RELEASE p14.