CVE-2020-7463
Estado: ModificadaMedia (5.5)—
In FreeBSD 12.1-STABLE before r364644, 11.4-STABLE before r364651, 12.1-RELEASE before p9, 11.4-RELEASE before p3, and 11.3-RELEASE before p13, improper handling in the kernel causes a use-after-free bug by sending large user messages from multiple threads on the same SCTP socket. The use-after-free situation may result in unintended kernel behaviour including a kernel panic.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 5.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.40%
- Percentil entre todas las CVEs puntuadas: 32
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (9)
CWE
- CWE-416
Referencias
- http://seclists.org/fulldisclosure/2021/Apr/49
- http://seclists.org/fulldisclosure/2021/Apr/50
- http://seclists.org/fulldisclosure/2021/Apr/57
- http://seclists.org/fulldisclosure/2021/Apr/58
- http://seclists.org/fulldisclosure/2021/Apr/59
- https://security.FreeBSD.org/advisories/FreeBSD-SA-20:25.sctp.asc
- https://support.apple.com/kb/HT212317
- https://support.apple.com/kb/HT212318
- https://support.apple.com/kb/HT212319
- https://support.apple.com/kb/HT212321
- https://support.apple.com/kb/HT212323
- https://support.apple.com/kb/HT212324
- https://support.apple.com/kb/HT212325
- http://seclists.org/fulldisclosure/2021/Apr/49
- http://seclists.org/fulldisclosure/2021/Apr/50
- http://seclists.org/fulldisclosure/2021/Apr/57
- http://seclists.org/fulldisclosure/2021/Apr/58
- http://seclists.org/fulldisclosure/2021/Apr/59
- https://security.FreeBSD.org/advisories/FreeBSD-SA-20:25.sctp.asc
- https://support.apple.com/kb/HT212317
- https://support.apple.com/kb/HT212318
- https://support.apple.com/kb/HT212319
- https://support.apple.com/kb/HT212321
- https://support.apple.com/kb/HT212323
- https://support.apple.com/kb/HT212324
- https://support.apple.com/kb/HT212325
JSON original (NVD)
Mostrar
{
"id": "CVE-2020-7463",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.9,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:N/C:N/I:N/A:C",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 6.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.5,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "secteam@freebsd.org",
"affectedData": [
{
"vendor": "n/a",
"product": "FreeBSD",
"versions": [
{
"status": "affected",
"version": "FreeBSD 12.1-RELEASE before p9, 11.4-RELEASE before p3, 11.3-RELEASE before p13"
}
]
}
]
}
],
"published": "2021-03-26T21:15:13.193",
"references": [
{
"url": "http://seclists.org/fulldisclosure/2021/Apr/49",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "secteam@freebsd.org"
},
{
"url": "http://seclists.org/fulldisclosure/2021/Apr/50",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "secteam@freebsd.org"
},
{
"url": "http://seclists.org/fulldisclosure/2021/Apr/57",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "secteam@freebsd.org"
},
{
"url": "http://seclists.org/fulldisclosure/2021/Apr/58",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "secteam@freebsd.org"
},
{
"url": "http://seclists.org/fulldisclosure/2021/Apr/59",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "secteam@freebsd.org"
},
{
"url": "https://security.FreeBSD.org/advisories/FreeBSD-SA-20:25.sctp.asc",
"tags": [
"Vendor Advisory"
],
"source": "secteam@freebsd.org"
},
{
"url": "https://support.apple.com/kb/HT212317",
"tags": [
"Third Party Advisory"
],
"source": "secteam@freebsd.org"
},
{
"url": "https://support.apple.com/kb/HT212318",
"tags": [
"Third Party Advisory"
],
"source": "secteam@freebsd.org"
},
{
"url": "https://support.apple.com/kb/HT212319",
"tags": [
"Third Party Advisory"
],
"source": "secteam@freebsd.org"
},
{
"url": "https://support.apple.com/kb/HT212321",
"tags": [
"Third Party Advisory"
],
"source": "secteam@freebsd.org"
},
{
"url": "https://support.apple.com/kb/HT212323",
"tags": [
"Third Party Advisory"
],
"source": "secteam@freebsd.org"
},
{
"url": "https://support.apple.com/kb/HT212324",
"tags": [
"Third Party Advisory"
],
"source": "secteam@freebsd.org"
},
{
"url": "https://support.apple.com/kb/HT212325",
"tags": [
"Third Party Advisory"
],
"source": "secteam@freebsd.org"
},
{
"url": "http://seclists.org/fulldisclosure/2021/Apr/49",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://seclists.org/fulldisclosure/2021/Apr/50",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://seclists.org/fulldisclosure/2021/Apr/57",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://seclists.org/fulldisclosure/2021/Apr/58",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://seclists.org/fulldisclosure/2021/Apr/59",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://security.FreeBSD.org/advisories/FreeBSD-SA-20:25.sctp.asc",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://support.apple.com/kb/HT212317",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://support.apple.com/kb/HT212318",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://support.apple.com/kb/HT212319",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://support.apple.com/kb/HT212321",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://support.apple.com/kb/HT212323",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://support.apple.com/kb/HT212324",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://support.apple.com/kb/HT212325",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-416"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In FreeBSD 12.1-STABLE before r364644, 11.4-STABLE before r364651, 12.1-RELEASE before p9, 11.4-RELEASE before p3, and 11.3-RELEASE before p13, improper handling in the kernel causes a use-after-free bug by sending large user messages from multiple threads on the same SCTP socket. The use-after-free situation may result in unintended kernel behaviour including a kernel panic."
},
{
"lang": "es",
"value": "En FreeBSD versiones 12.1-STABLE anteriores a r364644, 11.4-STABLE anteriores a r364651, 12.1-RELEASE anteriores a p9, 11.4-RELEASE anteriores a p3 y 11.3-RELEASE anteriores a p13, el manejo inapropiado en el kernel causa un bug de uso de la memoria previamente liberada mediante el envío de mensajes de usuario grandes de múltiples subprocesos en el mismo socket SCTP. La situación del uso de la memoria previamente liberada puede resultar en un comportamiento del kernel no deseado, incluyendo un pánico del kernel."
}
],
"lastModified": "2026-06-17T03:24:49.760",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:freebsd:freebsd:11.3:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F35957CE-AF9F-40CA-BDD1-FA6A0E73783F"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:11.3:p1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EA929713-B797-494A-853D-C121D9D69519"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:11.3:p10:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B87AF171-95AC-4DDA-8D94-694F85638B46"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:11.3:p11:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1CC8B031-41BB-4846-B092-7E4BC6F35D6B"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:11.3:p12:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "83E34012-BC9D-4F0C-AAE1-FE5767B4EED6"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:11.3:p2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3C3D8EDC-91D3-45B2-AC1D-EF4346D4A714"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:11.3:p3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EA5006FF-06A5-4D95-BF5B-29F26248D11F"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:11.3:p4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A705031B-FD63-4076-B92E-E826E11D7111"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:11.3:p5:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "11C1EFB1-68E5-45F4-A7E1-744574F290D1"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:11.3:p6:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "25F649A7-9265-4552-8934-BCE083363982"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:11.3:p7:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F202C856-5B95-4796-AC4A-1F210E7BAB8F"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:11.3:p8:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9419C866-C478-4CDE-A9A1-E592D8FF0933"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:11.3:p9:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2B6DFC23-A7A1-431A-9AD9-A820579F95F0"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:11.4:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4A865EA1-01D7-4E5A-9D13-80780F8A9D7A"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:11.4:p1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9FCA6A72-2A72-45FD-A43D-B5BF7C329121"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:11.4:p2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "90F9B3CB-3B60-4AA8-9EAF-4F0BE7D27691"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:12.1:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BD730B6A-F123-4685-ACB3-4F20AAAB77F3"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:12.1:p1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "508150E3-2C0C-4EEB-BFC9-BB5CEB404C06"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:12.1:p2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B5D692EF-A5D7-430E-91BA-4CD137343B66"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:12.1:p3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D50C60A7-4C9F-4636-92E9-9F5B8B01BE5B"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:12.1:p4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6C49F6C7-A740-42F4-93BB-512CBF334516"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:12.1:p5:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "402740C4-5B55-423F-BAD2-F742E1E21ADC"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:12.1:p6:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9DCAA10A-C612-45E0-84B7-55897F49D65E"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:12.1:p7:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CB6258A5-8066-48B8-A417-09A1547DD57A"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:12.1:p8:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6601C7C4-EC36-4EAA-90AC-D3156A2BF330"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:12.2:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "73D9C08B-8F5B-40C4-A5BD-B00D2E4C012D"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:apple:icloud:*:*:*:*:*:windows:*:*",
"vulnerable": true,
"matchCriteriaId": "338FA0C8-C5BA-4D8D-A196-EB728FCA228C",
"versionEndExcluding": "12.3"
},
{
"criteria": "cpe:2.3:a:apple:itunes:*:*:*:*:*:windows:*:*",
"vulnerable": true,
"matchCriteriaId": "24BA91CC-8D32-48F0-BB77-FF3ACA45176A",
"versionEndExcluding": "12.11.3"
},
{
"criteria": "cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "42EAB49D-2EA1-4B1F-BDAC-3165D1CB3759",
"versionEndExcluding": "14.1"
},
{
"criteria": "cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3EAAE2C1-EF21-4567-99F1-335D1EF955D1",
"versionEndExcluding": "14.5"
},
{
"criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C1E12568-6F17-458F-8216-3D6DBC8F6DEE",
"versionEndExcluding": "14.5"
},
{
"criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4E699CCC-31F5-458E-A59C-79B3AF143747",
"versionEndExcluding": "11.3",
"versionStartIncluding": "11.0"
},
{
"criteria": "cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D5B77841-F161-47AB-8043-3E0346E3AA25",
"versionEndExcluding": "14.5"
},
{
"criteria": "cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CFFFE00C-0AA6-4F60-ABF4-E68877BFD8F8",
"versionEndExcluding": "7.4"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "secteam@freebsd.org"
}