Vulnerability Description
A particular case of memory sharing is mishandled in the virtual memory system. This is very similar to SA-21:08.vm, but with a different root cause. An unprivileged local user process can maintain a mapping of a page after it is freed, allowing that process to read private data belonging to other processes or the kernel.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Freebsd | Freebsd | < 12.3 |
Related Weaknesses (CWE)
References
- https://security.freebsd.org/advisories/FreeBSD-SA-22:11.vm.ascVendor Advisory
- https://security.netapp.com/advisory/ntap-20240415-0008/Third Party Advisory
- https://security.freebsd.org/advisories/FreeBSD-SA-22:11.vm.ascVendor Advisory
- https://security.netapp.com/advisory/ntap-20240415-0008/Third Party Advisory
FAQ
What is CVE-2022-23091?
CVE-2022-23091 is a vulnerability with a CVSS score of 4.0 (MEDIUM). A particular case of memory sharing is mishandled in the virtual memory system. This is very similar to SA-21:08.vm, but with a different root cause. An unprivileged local user process can maintain ...
How severe is CVE-2022-23091?
CVE-2022-23091 has been rated MEDIUM with a CVSS base score of 4.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-23091?
Check the references section above for vendor advisories and patch information. Affected products include: Freebsd Freebsd.