CVE-2020-7469
The network stack may later dereference the pointer, potentially triggering a use-after-free.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.22%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In FreeBSD 12.2-STABLE before r367402, 11.4-STABLE before r368202, 12.2-RELEASE before p1, 12.1-RELEASE before p11 and 11.4-RELEASE before p5 the handler for a routing option caches a pointer into the packet buffer holding the ICMPv6 message. However, when processing subsequent options the packet buffer may be freed, rendering the cached pointer invalid. The network stack may later dereference the pointer, potentially triggering a use-after-free.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 1.22% probability · 67th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-416
- Affected
- freebsd/freebsd · netapp/clustered data ontap
- Source
- secteam@freebsd.org
References
- https://security.FreeBSD.org/advisories/FreeBSD-SA-20:31.icmp6.ascVendor Advisory
- https://security.netapp.com/advisory/ntap-20210720-0001/Third Party Advisory
- https://security.FreeBSD.org/advisories/FreeBSD-SA-20:31.icmp6.ascVendor Advisory
- https://security.netapp.com/advisory/ntap-20210720-0001/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.