10

CVE-2024-43102

umtx Kernel panic or Use-After-Free

Concurrent removals of certain anonymous shared memory mappings by using the UMTX_SHM_DESTROY sub-request of UMTX_OP_SHM can lead to decreasing the reference count of the object representing the mapping too many times, causing it to be freed too early.

A malicious code exercizing the UMTX_SHM_DESTROY sub-request in parallel can panic the kernel or enable further Use-After-Free attacks, potentially including code execution or Capsicum sandbox escape.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Freebsd ≫ Freebsd Version >= 13.0 < 13.3
Freebsd ≫ Freebsd Version 13.3 Update -
Freebsd ≫ Freebsd Version 13.3 Update p1
Freebsd ≫ Freebsd Version 13.3 Update p2
Freebsd ≫ Freebsd Version 13.3 Update p3
Freebsd ≫ Freebsd Version 13.3 Update p4
Freebsd ≫ Freebsd Version 13.3 Update p5
Freebsd ≫ Freebsd Version 13.4 Update beta3
Freebsd ≫ Freebsd Version 14.0 Update -
Freebsd ≫ Freebsd Version 14.0 Update beta5
Freebsd ≫ Freebsd Version 14.0 Update p1
Freebsd ≫ Freebsd Version 14.0 Update p2
Freebsd ≫ Freebsd Version 14.0 Update p3
Freebsd ≫ Freebsd Version 14.0 Update p4
Freebsd ≫ Freebsd Version 14.0 Update p5
Freebsd ≫ Freebsd Version 14.0 Update p6
Freebsd ≫ Freebsd Version 14.0 Update p7
Freebsd ≫ Freebsd Version 14.0 Update p8
Freebsd ≫ Freebsd Version 14.0 Update p9
Freebsd ≫ Freebsd Version 14.0 Update rc3
Freebsd ≫ Freebsd Version 14.0 Update rc4-p1
Freebsd ≫ Freebsd Version 14.1 Update -
Freebsd ≫ Freebsd Version 14.1 Update p1
Freebsd ≫ Freebsd Version 14.1 Update p2
Freebsd ≫ Freebsd Version 14.1 Update p3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.68% 0.476
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 10 3.9 6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CISA-ADP 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-416 Use After Free

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

CWE-911 Improper Update of Reference Count

The product uses a reference count to manage a resource, but it does not update or incorrectly updates the reference count.

https://security.freebsd.org/advisories/FreeBSD-SA-24:14.umtx.asc
Vendor Advisory
https://security.netapp.com/advisory/ntap-20240916-0001/