CVE-2024-39281: Freebsd

Medium severity, CVSS 5.3. EPSS: 0.5% chance of exploitation in the next 30 days.

The command ctl_persistent_reserve_out allows the caller to specify an arbitrary size which will be passed to the kernel's memory allocator.

Affected products

  • Freebsd Freebsd: from 14.1-RELEASE, before p6 (fixed in p6); from 13.4-RELEASE, before p2 (fixed in p2); from 13.3-RELEASE, before p8 (fixed in p8); any version

Published 2024-11-12. Last modified 2026-06-17.