CVE-2022-23092
Status: AnalyzedHigh (8.8)—
The implementation of lib9p's handling of RWALK messages was missing a bounds check needed when unpacking the message contents. The missing check means that the receipt of a specially crafted message will cause lib9p to overwrite unrelated memory.
The bug can be triggered by a malicious bhyve guest kernel to overwrite memory in the bhyve(8) process. This could potentially lead to user-mode code execution on the host, subject to bhyve's Capsicum sandbox.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Base score: 8.8
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.65%
- Percentile among all scored CVEs: 50
- Score date: 10/7/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-787
References
Raw JSON (NVD)
Show
{
"id": "CVE-2022-23092",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2022-23092",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2024-02-15T16:43:44.126625Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "secteam@freebsd.org",
"affectedData": [
{
"vendor": "FreeBSD",
"modules": [
"lib9p"
],
"product": "FreeBSD",
"versions": [
{
"status": "affected",
"version": "13.1-RELEASE",
"lessThan": "p1",
"versionType": "release"
},
{
"status": "affected",
"version": "13.0-RELEASE",
"lessThan": "p12",
"versionType": "release"
}
],
"defaultStatus": "unknown"
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:o:freebsd:freebsd:*:*:*:*:*:*:*:*"
],
"vendor": "freebsd",
"product": "freebsd",
"versions": [
{
"status": "affected",
"version": "13.1-release",
"lessThan": "p1",
"versionType": "custom"
},
{
"status": "affected",
"version": "13.0-release",
"lessThan": "p12",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2024-02-15T06:15:45.190",
"references": [
{
"url": "https://security.freebsd.org/advisories/FreeBSD-SA-22:12.lib9p.asc",
"tags": [
"Vendor Advisory"
],
"source": "secteam@freebsd.org"
},
{
"url": "https://security.netapp.com/advisory/ntap-20240415-0009/",
"tags": [
"Third Party Advisory"
],
"source": "secteam@freebsd.org"
},
{
"url": "https://security.freebsd.org/advisories/FreeBSD-SA-22:12.lib9p.asc",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://security.netapp.com/advisory/ntap-20240415-0009/",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"description": [
{
"lang": "en",
"value": "CWE-787"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The implementation of lib9p's handling of RWALK messages was missing a bounds check needed when unpacking the message contents. The missing check means that the receipt of a specially crafted message will cause lib9p to overwrite unrelated memory.\n\nThe bug can be triggered by a malicious bhyve guest kernel to overwrite memory in the bhyve(8) process. This could potentially lead to user-mode code execution on the host, subject to bhyve's Capsicum sandbox."
},
{
"lang": "es",
"value": "A la implementación del manejo de mensajes RWALK por parte de lib9p le faltaba una verificación de los límites necesaria al descomprimir el contenido del mensaje. La verificación faltante significa que la recepción de un mensaje especialmente manipulado hará que lib9p sobrescriba la memoria no relacionada. El error puede ser provocado por un kernel invitado de bhyve malicioso que sobrescribe la memoria en el proceso bhyve(8). Esto podría conducir potencialmente a la ejecución de código en modo de usuario en el host, sujeto al entorno limitado de Capsicum de bhyve."
}
],
"lastModified": "2026-06-17T04:29:29.690",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:freebsd:freebsd:13.0:beta1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7412DBD8-BB1F-48A8-AAE1-BA5C8D7BDDF7"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:13.0:beta2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "833DFF5B-BC50-424A-ABCF-EC632F421B76"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:13.0:beta3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9F27016E-4117-4094-BB7A-9C56E38024D9"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:13.0:beta3-p1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EC7326E3-908D-47A1-B848-3AA7F34B3DD3"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:13.0:beta4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B149BF69-951D-47B4-996C-9E4773DA75B7"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:13.0:p1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "04A0E266-714C-4753-A652-A51F25582C78"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:13.0:p10:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D133E8E0-4E88-451C-9693-5DE5C3092AD2"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:13.0:p11:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FF1A096F-EC60-4C7D-AE40-D1DDAC9D4E40"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:13.0:p2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "556111A1-C236-4DF6-9438-F9C874451A58"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:13.0:p3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1673F16B-463A-492C-B66F-48917008F7F5"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:13.0:p4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E73B211F-2CA9-47A4-B318-F24CC1C7E589"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:13.0:p5:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7C13DDEF-FF5F-4723-9C25-4EA66AE2CEDD"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:13.0:p6:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7A942EA9-0DD3-44BC-B582-C680BA34E88F"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:13.0:p7:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "689BC10B-0404-4468-B604-9D96337F9BD1"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:13.0:p8:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "38DDAA43-3E9C-479F-8416-E3B9BE23C31B"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:13.0:p9:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AE490480-1EA1-4684-A643-9749E87A8448"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:13.0:rc1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FC271C93-EB83-4301-B7BA-F3249B71B1EA"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:13.0:rc2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "04329338-AC28-4A74-BE6B-CE8EC6CC37B7"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:13.0:rc3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "ADBA841F-5C83-4759-84B7-B59DA1B12EA8"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:13.0:rc4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6A8F38B3-A6DA-4178-A2BD-0D4F0267C384"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:13.0:rc5:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9BB028A0-70F6-42DA-9E5A-F7AAF74ED45B"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:13.0:rc5-p1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "00D28E4E-022B-482E-9952-7F7F47C427C2"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:13.1:b1-p1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "66364EA4-83B1-4597-8C18-D5633B361A9C"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:13.1:b2-p2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EF9292DD-EFB1-4B50-A941-7485D901489F"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:13.1:rc1-p1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B536EE52-ED49-4A85-BC9D-A27828D5A961"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "secteam@freebsd.org"
}