CVE-2022-23091: Memory disclosure by stale virtual memory mapping
A particular case of memory sharing is mishandled in the virtual memory system. This is very similar to SA-21:08.vm, but with a different root cause.
An unprivileged local user process can maintain a mapping of a page after it is freed, allowing that process to read private data belonging to other processes or the kernel.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-23091?
CVE-2022-23091 has been classified with a high severity due to its potential impact on sensitive data exposure.
How do I fix CVE-2022-23091?
To remediate CVE-2022-23091, it is recommended to upgrade to a patched version of FreeBSD that addresses the vulnerability.
Who is affected by CVE-2022-23091?
CVE-2022-23091 affects users running FreeBSD versions up to 12.3 and specific 13.0 versions, including various beta and patch releases.
What type of vulnerability is CVE-2022-23091?
CVE-2022-23091 is a memory management vulnerability in the virtual memory system that may allow unauthorized data access.
Can CVE-2022-23091 be exploited remotely?
No, CVE-2022-23091 can only be exploited by local unprivileged users on the affected FreeBSD systems.