In OpenBSD 7.4 before errata 002 and OpenBSD 7.3 before errata 019, a network buffer that had to be split at certain length that could crash the kernel after receiving specially crafted escape sequences.
The product does not correctly calculate the size to be used when allocating a buffer, which could lead to a buffer overflow.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Openbsd | Openbsd | * | 7.3 (excluding) |
Openbsd | Openbsd | 7.3 (including) | 7.3 (including) |
Openbsd | Openbsd | 7.3-errata_001 (including) | 7.3-errata_001 (including) |
Openbsd | Openbsd | 7.3-errata_002 (including) | 7.3-errata_002 (including) |
Openbsd | Openbsd | 7.3-errata_003 (including) | 7.3-errata_003 (including) |
Openbsd | Openbsd | 7.3-errata_004 (including) | 7.3-errata_004 (including) |
Openbsd | Openbsd | 7.3-errata_005 (including) | 7.3-errata_005 (including) |
Openbsd | Openbsd | 7.3-errata_006 (including) | 7.3-errata_006 (including) |
Openbsd | Openbsd | 7.3-errata_007 (including) | 7.3-errata_007 (including) |
Openbsd | Openbsd | 7.3-errata_008 (including) | 7.3-errata_008 (including) |
Openbsd | Openbsd | 7.3-errata_009 (including) | 7.3-errata_009 (including) |
Openbsd | Openbsd | 7.3-errata_010 (including) | 7.3-errata_010 (including) |
Openbsd | Openbsd | 7.3-errata_011 (including) | 7.3-errata_011 (including) |
Openbsd | Openbsd | 7.3-errata_012 (including) | 7.3-errata_012 (including) |
Openbsd | Openbsd | 7.3-errata_013 (including) | 7.3-errata_013 (including) |
Openbsd | Openbsd | 7.3-errata_014 (including) | 7.3-errata_014 (including) |
Openbsd | Openbsd | 7.3-errata_015 (including) | 7.3-errata_015 (including) |
Openbsd | Openbsd | 7.3-errata_016 (including) | 7.3-errata_016 (including) |
Openbsd | Openbsd | 7.3-errata_017 (including) | 7.3-errata_017 (including) |
Openbsd | Openbsd | 7.3-errata_018 (including) | 7.3-errata_018 (including) |
Openbsd | Openbsd | 7.4 (including) | 7.4 (including) |
Openbsd | Openbsd | 7.4-errata_001 (including) | 7.4-errata_001 (including) |