Vulnerability Description
In FreeBSD 12.1-STABLE before r357490, 12.1-RELEASE before 12.1-RELEASE-p3, 11.3-STABLE before r357489, and 11.3-RELEASE before 11.3-RELEASE-p7, incorrect use of a user-controlled pointer in the epair virtual network module allowed vnet jailed privileged users to panic the host system and potentially execute arbitrary code in the kernel.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Freebsd | Freebsd | 11.3 |
Related Weaknesses (CWE)
References
- https://security.FreeBSD.org/advisories/FreeBSD-SA-20:07.epair.ascPatchVendor Advisory
- https://security.FreeBSD.org/advisories/FreeBSD-SA-20:07.epair.ascPatchVendor Advisory
FAQ
What is CVE-2020-7452?
CVE-2020-7452 is a vulnerability with a CVSS score of 9.1 (CRITICAL). In FreeBSD 12.1-STABLE before r357490, 12.1-RELEASE before 12.1-RELEASE-p3, 11.3-STABLE before r357489, and 11.3-RELEASE before 11.3-RELEASE-p7, incorrect use of a user-controlled pointer in the epair...
How severe is CVE-2020-7452?
CVE-2020-7452 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-7452?
Check the references section above for vendor advisories and patch information. Affected products include: Freebsd Freebsd.