SB2020061013 - Privilege escalation in FreeBSD



SB2020061013 - Privilege escalation in FreeBSD

Published: June 10, 2020

Security Bulletin ID SB2020061013
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Physical access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Resource management error (CVE-ID: CVE-2020-7456)

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to improper management of internal resources. The the push/pop level is not restored within the processing of the same HID item, an invalid memory location may be used for subsequent HID item processing. An attacker with physical access to a USB port may be able to use a specially crafted USB device to gain kernel or user-space code execution.


Remediation

Install update from vendor's website.