Vulnerability Details CVE-2020-7457
In FreeBSD 12.1-STABLE before r359565, 12.1-RELEASE before p7, 11.4-STABLE before r362975, 11.4-RELEASE before p1, and 11.3-RELEASE before p11, missing synchronization in the IPV6_2292PKTOPTIONS socket option set handler contained a race condition allowing a malicious application to modify memory after being freed, possibly resulting in code execution.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.646
EPSS Ranking 98.3%
CVSS Severity
CVSS v3 Score 8.1
CVSS v2 Score 6.8
Products affected by CVE-2020-7457
-
cpe:2.3:o:freebsd:freebsd:11.3
-
cpe:2.3:o:freebsd:freebsd:11.4
-
cpe:2.3:o:freebsd:freebsd:12.1