#VU26238 Permissions, Privileges, and Access Controls in FreeBSD - CVE-2020-7452
Published: March 19, 2020
FreeBSD
FreeBSD Foundation
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to incorrect usage of potentially user-controlled pointer within the epair interface in kernel. A local vnet jailed user with root level access (or the PRIV_NET_IFCREATE privilege) cab cause the system panic or execute arbitrary code kernel privileges on the system.