Vulnerability Description
In 11.4-PRERELEASE before r360733 and 11.3-RELEASE before p13, improper mbuf handling in the kernel causes a use-after-free bug by sending IPv6 Hop-by-Hop options over the loopback interface. The use-after-free situation may result in unintended kernel behaviour including a kernel panic.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Freebsd | Freebsd | 11.3 |
Related Weaknesses (CWE)
References
- https://security.FreeBSD.org/advisories/FreeBSD-SA-20:24.ipv6.ascVendor Advisory
- https://security.FreeBSD.org/advisories/FreeBSD-SA-20:24.ipv6.ascVendor Advisory
FAQ
What is CVE-2020-7462?
CVE-2020-7462 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In 11.4-PRERELEASE before r360733 and 11.3-RELEASE before p13, improper mbuf handling in the kernel causes a use-after-free bug by sending IPv6 Hop-by-Hop options over the loopback interface. The use-...
How severe is CVE-2020-7462?
CVE-2020-7462 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-7462?
Check the references section above for vendor advisories and patch information. Affected products include: Freebsd Freebsd.