CVE-2022-23090: AIO credential reference count leak
The aioaqueue function, used by the liolistio system call, fails to release a reference to a credential in an error case.
An attacker may cause the reference count to overflow, leading to a use after free (UAF).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-23090?
CVE-2022-23090 is considered to have a high severity due to the potential for a use after free vulnerability that can be exploited by attackers.
How do I fix CVE-2022-23090?
To fix CVE-2022-23090, update your FreeBSD system to the latest version that addresses this vulnerability.
What versions of FreeBSD are affected by CVE-2022-23090?
CVE-2022-23090 affects FreeBSD versions 12.3-beta1, 12.3-p1 to 12.3-p5, and various 13.0 beta and release candidates.
What is the nature of the vulnerability in CVE-2022-23090?
The vulnerability in CVE-2022-23090 relates to the aio_aqueue function failing to release a reference to a credential during error cases, allowing for reference count overflow.
Can CVE-2022-23090 lead to system exploitation?
Yes, CVE-2022-23090 can potentially lead to exploitation via a use after free condition, making it a critical issue for users of affected FreeBSD versions.