#VU34100 Race condition in FreeBSD - CVE-2020-7460
Published: August 7, 2020
FreeBSD
FreeBSD Foundation
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to the sendmsg system call in the compat32 subsystem on 64-bit platforms has a time-of-check to time-of-use issue. A local user can tun a specially crafted program from userspace and modify control message headers after they are validation.
Successful exploitation of the vulnerability may allow an attacker to escalate privileges on the system.