7.5

CVE-2023-52558

OpenBSD 7.4 and 7.3 m_split() network buffer kernel crash

In OpenBSD 7.4 before errata 002 and OpenBSD 7.3 before errata 019, a network buffer that had to be split at certain length that could crash the kernel after receiving specially crafted escape sequences.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Openbsd ≫ Openbsd Version < 7.3
Openbsd ≫ Openbsd Version 7.3 Update -
Openbsd ≫ Openbsd Version 7.3 Update errata_001
Openbsd ≫ Openbsd Version 7.3 Update errata_002
Openbsd ≫ Openbsd Version 7.3 Update errata_003
Openbsd ≫ Openbsd Version 7.3 Update errata_004
Openbsd ≫ Openbsd Version 7.3 Update errata_005
Openbsd ≫ Openbsd Version 7.3 Update errata_006
Openbsd ≫ Openbsd Version 7.3 Update errata_007
Openbsd ≫ Openbsd Version 7.3 Update errata_008
Openbsd ≫ Openbsd Version 7.3 Update errata_009
Openbsd ≫ Openbsd Version 7.3 Update errata_010
Openbsd ≫ Openbsd Version 7.3 Update errata_011
Openbsd ≫ Openbsd Version 7.3 Update errata_012
Openbsd ≫ Openbsd Version 7.3 Update errata_013
Openbsd ≫ Openbsd Version 7.3 Update errata_014
Openbsd ≫ Openbsd Version 7.3 Update errata_015
Openbsd ≫ Openbsd Version 7.3 Update errata_016
Openbsd ≫ Openbsd Version 7.3 Update errata_017
Openbsd ≫ Openbsd Version 7.3 Update errata_018
Openbsd ≫ Openbsd Version 7.4 Update -
Openbsd ≫ Openbsd Version 7.4 Update errata_001
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.7% 0.483
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-131 Incorrect Calculation of Buffer Size

The product does not correctly calculate the size to be used when allocating a buffer, which could lead to a buffer overflow.

https://ftp.openbsd.org/pub/OpenBSD/patches/7.3/common/019_msplit.patch.sig
Patch
https://ftp.openbsd.org/pub/OpenBSD/patches/7.4/common/002_msplit.patch.sig
Patch
https://github.com/openbsd/src/commit/7b4d35e0a60ba1dd4daf4b1c2932020a22463a89
Patch