Stack-based buffer overflow in FreeBSD - CVE-2025-0373
Published: January 29, 2025 / Updated: July 30, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to stack-based buffer overflow in the VOP_VPTOFH() implementation of the cd9660, tarfs, and ext2fs filesystems when handling NFS access to exported filesystems. A remote attacker can mount and access a crafted NFS export to cause a denial of service.
Only 64-bit systems that export a cd9660, tarfs, or ext2fs filesystem via NFS are vulnerable. Further exploitation such as bypassing file permission checks or remote kernel code execution is noted as potentially possible but has not been demonstrated.