CVE-2013-3077: Freebsd
High severity, CVSS 7.2. EPSS: 0.4% chance of exploitation in the next 30 days.
Multiple integer overflows in the IP_MSFILTER and IPV6_MSFILTER features in (1) sys/netinet/in_mcast.c and (2) sys/netinet6/in6_mcast.c in the multicast implementation in the kernel in FreeBSD 8.3 through 9.2-PRERELEASE allow local users to bypass intended restrictions on kernel-memory read and write operations, and consequently gain privileges, via vectors involving a large number of source-filter entries.
Affected products
- Freebsd Freebsd: version 8.3 only; version 9.0 only; version 9.1 only; version 9.2 only
Published 2013-08-28. Last modified 2026-06-16.