FreeBSD-SA-24:18.ctl impacted systems

2024-11-18 Thread Wall, Stephen
Good day, folks. I am seeking clarification of statements in https://www.freebsd.org/security/advisories/FreeBSD-SA-24:18.ctl.asc. Section III, Impact says “A malicious guest could cause a Denial of Service (DoS) on the host.” Does this imply that only FreeBSD systems acting as a Virtualization

Re: CVE-2024-39281 allegedly not fixed in 14.1

2024-11-18 Thread Dag-Erling Smørgrav
Lasse Kliemann writes: > Since a few days, I see this warning: > > Checking for security vulnerabilities in base (userland & kernel): > Database fetched: 2024-11-15T19:30+00:00 > FreeBSD-kernel-14.1_5 is vulnerable: > FreeBSD -- Unbounded allocation in ctl(4) CAM Target Layer > CVE: CVE-2024-3