FreeBSD Ping Stack-Based Overflow Security Advisory
ID: 1dbe3720-8b51-5871-b263-f612d45be770
STIX ID: report--1dbe3720-8b51-5871-b263-f612d45be770
Feed Name: Zscaler Security Research Blog
This report describes CVE-2022-23093, a stack overflow in FreeBSD's /sbin/ping pr_pack() function triggered when IP option headers are present in ICMP responses or quoted packets; the overflow can reach up to 40 bytes and may lead to crashes or potential remote code execution. The advisory covers affected versions (all supported FreeBSD), technical analysis of how hlen and memcpy cause the overflow, recommended mitigations (patching, backporting, firewalling/blocking ICMP with IP options, restricting ping), and references to the FreeBSD advisory and external trackers. Zscaler confirms its cloud was not impacted.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
