7.8
CWE
367
Advisory Published
Updated

CVE-2022-23084: Potential jail escape vulnerabilities in netmap

First published: Thu Feb 15 2024(Updated: )

The total size of the user-provided nmreq to nmreq_copyin() was first computed and then trusted during the copyin. This time-of-check to time-of-use bug could lead to kernel memory corruption. On systems configured to include netmap in their devfs_ruleset, a privileged process running in a jail can affect the host environment.

Credit: secteam@freebsd.org

Affected SoftwareAffected VersionHow to fix
FreeBSD Kernel>=12.0<12.3
FreeBSD Kernel=12.3
FreeBSD Kernel=12.3-p1
FreeBSD Kernel=12.3-p2
FreeBSD Kernel=12.3-p3
FreeBSD Kernel=12.3-p4
FreeBSD Kernel=13.0
FreeBSD Kernel=13.0-beta1
FreeBSD Kernel=13.0-beta2
FreeBSD Kernel=13.0-beta3
FreeBSD Kernel=13.0-beta3-p1
FreeBSD Kernel=13.0-beta4
FreeBSD Kernel=13.0-p1
FreeBSD Kernel=13.0-p10
FreeBSD Kernel=13.0-p2
FreeBSD Kernel=13.0-p3
FreeBSD Kernel=13.0-p4
FreeBSD Kernel=13.0-p5
FreeBSD Kernel=13.0-p6
FreeBSD Kernel=13.0-p7
FreeBSD Kernel=13.0-p8
FreeBSD Kernel=13.0-p9
FreeBSD Kernel=13.0-rc1
FreeBSD Kernel=13.0-rc2
FreeBSD Kernel=13.0-rc3
FreeBSD Kernel=13.0-rc4
FreeBSD Kernel=13.0-rc5
FreeBSD Kernel=13.0-rc5-p1

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2022-23084?

    CVE-2022-23084 is classified as a high-severity vulnerability due to its potential to lead to kernel memory corruption.

  • How do I fix CVE-2022-23084?

    To address CVE-2022-23084, users should update to the latest patched version of FreeBSD that resolves this vulnerability.

  • What systems are affected by CVE-2022-23084?

    CVE-2022-23084 affects FreeBSD versions 12.0 through 12.3 and versions from 13.0 to 13.0-rc5.

  • What kind of exploit can result from CVE-2022-23084?

    CVE-2022-23084 can be exploited by a privileged process to potentially corrupt kernel memory, leading to system instability.

  • How can I identify if my FreeBSD system is vulnerable to CVE-2022-23084?

    You can check the version of FreeBSD running on your system to determine if it falls within the affected version range for CVE-2022-23084.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203