A memory corruption vulnerability was found in the kernel function kern_getfsstat in MidnightBSD before 1.2.7 and 1.3 through 2020-08-19, and FreeBSD through 11.4, that allows an attacker to trigger an invalid free and crash the system via a crafted size value in conjunction with an invalid mode.
{
"unresolved_ranges": [
{
"vendor_product": "freebsd:freebsd",
"cpes": [
"cpe:2.3:o:freebsd:freebsd:*:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"last_affected": "11.4"
}
],
"source": "CPE_RANGE"
},
{
"vendor_product": "midnightbsd:midnightbsd",
"cpes": [
"cpe:2.3:a:midnightbsd:midnightbsd:*:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "1.3"
},
{
"last_affected": "2020-08-19"
}
],
"source": "CPE_RANGE"
}
]
}{
"cpe": "cpe:2.3:a:midnightbsd:midnightbsd:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "1.2.7"
}
],
"source": "CPE_RANGE"
}