CVE-2024-29937: Freebsd

Critical severity, CVSS 9.8. EPSS: 1.8% chance of exploitation in the next 30 days.

NFS in a BSD derived codebase, as used in OpenBSD through 7.4 and FreeBSD through 14.0-RELEASE, allows remote attackers to execute arbitrary code via a bug that is unrelated to memory corruption.

Affected products

  • Freebsd Freebsd: version 14.0 only
  • OpenBSD OpenBSD: up to and including 7.4

Published 2024-04-11. Last modified 2026-06-17.