In FreeBSD 12.2-STABLE before r367402, 11.4-STABLE before r368202, 12.2-RELEASE before p1, 12.1-RELEASE before p11 and 11.4-RELEASE before p5 the handler for a routing option caches a pointer into the packet buffer holding the ICMPv6 message. However, when processing subsequent options the packet buffer may be freed, rendering the cached pointer invalid. The network stack may later dereference the pointer, potentially triggering a use-after-free.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: freebsd

Published: 2021-06-04T11:55:55

Updated: 2021-07-20T10:06:38

Reserved: 2020-01-21T00:00:00


Link: CVE-2020-7469

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-06-04T12:15:07.450

Modified: 2022-05-31T15:54:34.257


Link: CVE-2020-7469

JSON object: View

cve-icon Redhat Information

No data.

CWE