#VU61914 Heap-based buffer overflow in FreeBSD - CVE-2022-23088
Published: April 6, 2022 / Updated: June 1, 2022
FreeBSD
FreeBSD Foundation
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error within the 802.11 beacon handling routine in FreeBSD Wi-Fi client. A remote attacker with control over the Wi-Fi hotspot can send specially beacon crafted frames to the FreeBSD Wi-Fi client in scanning mode, trigger a heap-based buffer overflow and execute arbitrary code on the system.