peter bassill · operator
$ cve CVE-2022-23088 JSON

CVE-2022-23088

9.8
CRITICAL · CVSS 3.1 · EPSS 3.6% (pctl 89)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

The 802.11 beacon handling routine failed to validate the length of an IEEE 802.11s Mesh ID before copying it to a heap-allocated buffer. While a FreeBSD Wi-Fi client is in scanning mode (i.e., not associated with a SSID) a malicious beacon frame may overwrite kernel memory, leading to remote code execution.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.62% — more likely to be exploited than 89% of all CVEs
WeaknessCWE-94
On CISA KEVno
Public exploitnone known
Published2024-02-15
Last modified2026-06-17

Affected (1)

VendorProduct
freebsdfreebsd

References

→ the Explorer  ·  watch your stack  ·  NVD