Vulnerability Database

289,599

Total vulnerabilities in the database

CVE-2022-23086

Handlers for *_CFG_PAGE read / write ioctls in the mpr, mps, and mpt drivers allocated a buffer of a caller-specified size, but copied to it a fixed size header. Other heap content would be overwritten if the specified size was too small.

Users with access to the mpr, mps or mpt device node may overwrite heap data, potentially resulting in privilege escalation. Note that the device node is only accessible to root and members of the operator group.

  • Published: Feb 15, 2024
  • Updated: May 4, 2025
  • CVE: CVE-2022-23086
  • Severity: High
  • Exploit:

CVSS v3:

  • Severity: High
  • Score: 7.8
  • AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CWEs:

Software From Fixed in
freebsd / freebsd 13.0-rc5 13.0-rc5.x
freebsd / freebsd 13.0-rc1 13.0-rc1.x
freebsd / freebsd 13.0-rc2 13.0-rc2.x
freebsd / freebsd 13.0-rc4 13.0-rc4.x
freebsd / freebsd 13.0-beta1 13.0-beta1.x
freebsd / freebsd 13.0-beta2 13.0-beta2.x
freebsd / freebsd 12.3-p1 12.3-p1.x
freebsd / freebsd 13.0 13.0.x
freebsd / freebsd 13.0-beta3 13.0-beta3.x
freebsd / freebsd 13.0-beta3-p1 13.0-beta3-p1.x
freebsd / freebsd 13.0-beta4 13.0-beta4.x
freebsd / freebsd 13.0-p1 13.0-p1.x
freebsd / freebsd 13.0-p2 13.0-p2.x
freebsd / freebsd 13.0-p3 13.0-p3.x
freebsd / freebsd 13.0-p4 13.0-p4.x
freebsd / freebsd 13.0-p5 13.0-p5.x
freebsd / freebsd 13.0-rc3 13.0-rc3.x
freebsd / freebsd 13.0-rc5-p1 13.0-rc5-p1.x
freebsd / freebsd 12.0 12.3
freebsd / freebsd 12.3 12.3.x
freebsd / freebsd 12.3-p2 12.3-p2.x
freebsd / freebsd 12.3-p3 12.3-p3.x
freebsd / freebsd 12.3-p4 12.3-p4.x
freebsd / freebsd 13.0-p10 13.0-p10.x
freebsd / freebsd 13.0-p6 13.0-p6.x
freebsd / freebsd 13.0-p7 13.0-p7.x
freebsd / freebsd 13.0-p8 13.0-p8.x
freebsd / freebsd 13.0-p9 13.0-p9.x