cbcvebase.
CVE-2020-7463
published 2021-03-26

CVE-2020-7463: In FreeBSD 12.1-STABLE before r364644, 11.4-STABLE before r364651, 12.1-RELEASE before p9, 11.4-RELEASE before p3, and 11.3-RELEASE before p13, improper…

medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
In FreeBSD 12.1-STABLE before r364644, 11.4-STABLE before r364651, 12.1-RELEASE before p9, 11.4-RELEASE before p3, and 11.3-RELEASE before p13, improper handling in the kernel causes a use-after-free bug by sending large user messages from multiple threads on the same SCTP socket. The use-after-free situation may result in unintended kernel behaviour including a kernel panic.

Affected

15 ranges
VendorProductVersion rangeFixed in
appleicloud< 12.312.3
appleios_14.5_and_ipados
appleipados< 14.514.5
appleiphone_os< 14.514.5
appleitunes< 12.11.312.11.3
applemacos>= 11.0 < 11.311.3
applemacos_big_sur
applesafari< 14.114.1
appletvos< 14.514.5
applewatchos< 7.47.4
freebsdfreebsd
freebsdfreebsd
freebsdfreebsd
freebsdfreebsd
freebsdfreebsd