CVE-2024-41721: Freebsd

High severity, CVSS 8.1. EPSS: 0.8% chance of exploitation in the next 30 days.

An insufficient boundary validation in the USB code could lead to an out-of-bounds read on the heap, which could potentially lead to an arbitrary write and remote code execution.

Affected products

  • Freebsd Freebsd: from 14.1-RELEASE, before p5 (fixed in p5); from 14.0-RELEASE, before p11 (fixed in p11); from 13.4-RELEASE, before p1 (fixed in p1); from 13.3-RELEASE, before p7 (fixed in p7); from 14.1, before 14.1_p5 (fixed in 14.1_p5); from 14.0, before 14.0_p11 (fixed in 14.0_p11); …

Published 2024-09-20. Last modified 2026-06-17.