Omniosce Omnios vulnerabilities

4 known vulnerabilities affecting omniosce/omnios.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH2MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2021-43395MEDIUMCVSS 5.5vr1510382022-12-26
CVE-2021-43395 [MEDIUM] CWE-667 CVE-2021-43395: An issue was discovered in illumos before f859e7171bb5db34321e45585839c6c3200ebb90, OmniOS Community An issue was discovered in illumos before f859e7171bb5db34321e45585839c6c3200ebb90, OmniOS Community Edition r151038, OpenIndiana Hipster 2021.04, and SmartOS 20210923. A local unprivileged user can cause a deadlock and kernel panic via crafted rename and rmdir calls on tmpfs filesystems. Oracle Solaris 10 and 11 is also affected.
nvd
CVE-2020-27678CRITICALCVSS 9.8fixed in r151030by≥ r151032, ≤ r151032ay+1 more2020-10-26
CVE-2020-27678 [CRITICAL] CWE-120 CVE-2020-27678: An issue was discovered in illumos before 2020-10-22, as used in OmniOS before r151030by, r151032ay, An issue was discovered in illumos before 2020-10-22, as used in OmniOS before r151030by, r151032ay, and r151034y and SmartOS before 20201022. There is a buffer overflow in parse_user_name in lib/libpam/pam_framework.c.
nvd
CVE-2020-24718HIGHCVSS 8.2≤ r1510342020-09-25
CVE-2020-24718 [HIGH] CWE-862 CVE-2020-24718: bhyve, as used in FreeBSD through 12.1 and illumos (e.g., OmniOS CE through r151034 and OpenIndiana bhyve, as used in FreeBSD through 12.1 and illumos (e.g., OmniOS CE through r151034 and OpenIndiana through Hipster 2020.04), does not properly restrict VMCS and VMCB read/write operations, as demonstrated by a root user in a container on an Intel system, who can gain privileges by modifying VMCS_HOST_RIP.
nvd
CVE-2019-19396HIGHCVSS 7.5fixed in r1510302019-11-29
CVE-2019-19396 [HIGH] CWE-20 CVE-2019-19396: illumos, as used in OmniOS Community Edition before r151030y, allows a kernel crash via an applicati illumos, as used in OmniOS Community Edition before r151030y, allows a kernel crash via an application with multiple threads calling sendmsg concurrently over a single socket, because uts/common/inet/ip/ip_attr.c mishandles conn_ixa dereferences.
nvd