CVE-2024-45288: Freebsd
High severity, CVSS 8.4. EPSS: 0.3% chance of exploitation in the next 30 days.
A missing null-termination character in the last element of an nvlist array string can lead to writing outside the allocated buffer.
Affected products
- Freebsd Freebsd: from 14.1-RELEASE, before p4 (fixed in p4); from 14.0-RELEASE, before p10 (fixed in p10); from 13.3-RELEASE, before p6 (fixed in p6); from 14.1, before 14.1_p4 (fixed in 14.1_p4); from 14.0, before 14.0_p10 (fixed in 14.0_p10); from 13.3, before 13.3_p6 (fixed in 13.3_p6)
Published 2024-09-05. Last modified 2026-06-17.