In OpenBSD 7.5 before errata 008 and OpenBSD 7.4 before errata 021, avoid possible mbuf double free in NFS client and server implementation, do not use uninitialized variable in error handling of NFS server.
The first vulnerability (CWE-415) consists of the possibility of freeing the same memory area twice (mbuf double free) in the NFS client and server code, which can lead to heap corruption. The second vulnerability (CWE-457) concerns the use of an uninitialized variable in the error handling path on the NFS server side, which can result in unpredictable system behavior or disclosure of data from memory. Both vulnerabilities are available to a network attacker without the need for authentication.
An attacker can lead to unauthorized code execution (RCE), system suspension or crash, and potentially read or modify data in the operating memory of the NFS server or client.
Official manufacturer errata should be applied: for OpenBSD 7.5 — errata 008 (patch available at https://ftp.openbsd.org/pub/OpenBSD/patches/7.5/common/008_nfs.patch.sig), for OpenBSD 7.4 — errata 021 (patch available at https://ftp.openbsd.org/pub/OpenBSD/patches/7.4/common/021_nfs.patch.sig). Until the patch is deployed, it is recommended to restrict access to NFS services at the firewall level.
OpenBSD 7.5 before errata 008 and OpenBSD 7.4 before errata 021 — systems operating as NFS client or server.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:X/U:XOpenbsd
OSOpenbsd7.47.5< 7.4
Related vulnerabilities
RCE w implementacji NFS w OpenBSD i FreeBSD — zdalne wykonanie kodu
Double free / use-after-free w LibreSSL i OpenBSD po wywołaniu SSL_clear
Authentication bypass przez odrzucanie błędów weryfikacji certyfikatów w LibreSSL/OpenBSD
OpenIKED: pominięcie uwierzytelnienia przez błędną weryfikację klucza publicznego
OpenBSD/dietlibc: generator liczb losowych zwraca 0 przy seedzie 0