FreshPorts - VuXML

This page displays vulnerability information about FreeBSD Ports.

The VUXML data was last processed by FreshPorts on 2025-01-25 14:24:43 UTC

List all Vulnerabilities, by package

List all Vulnerabilities, by date

k68

These are the vulnerabilities relating to the commit you have selected:

VuXML IDDescription
7e079ce2-6b51-11ef-9a62-002590c1f29cFreeBSD -- umtx Kernel panic or Use-After-Free

Problem Description:

Concurrent removals of such a mapping by using the UMTX_SHM_DESTROY sub-request of UMTX_OP_SHM can lead to decreasing the reference count of the object representing the mapping too many times, causing it to be freed too early.

Impact:

A malicious code exercizing the UMTX_SHM_DESTROY sub-request in parallel can panic the kernel or enable further Use-After-Free attacks, potentially including code execution or Capsicum sandbox escape.


Discovery 2024-09-04
Entry 2024-09-05
FreeBSD
>= 14.1 lt 14.1_4

>= 14.0 lt 14.0_10

>= 13.3 lt 13.3_6

CVE-2024-43102
SA-24:14.umtx