Critical severity10.0NVD Advisory· Published Sep 5, 2024· Updated Jun 17, 2026
CVE-2024-43102
CVE-2024-43102
Description
Concurrent removals of certain anonymous shared memory mappings by using the UMTX_SHM_DESTROY sub-request of UMTX_OP_SHM can lead to decreasing the reference count of the object representing the mapping too many times, causing it to be freed too early.
A malicious code exercizing the UMTX_SHM_DESTROY sub-request in parallel can panic the kernel or enable further Use-After-Free attacks, potentially including code execution or Capsicum sandbox escape.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
28(expand)+ 26 more
- (no CPE)
- (no CPE)range: 14.1-RELEASE
- cpe:2.3:o:freebsd:freebsd:*:*:*:*:*:*:*:*range: >=13.0,<13.3
- cpe:2.3:o:freebsd:freebsd:13.3:-:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:13.3:p1:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:13.3:p2:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:13.3:p3:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:13.3:p4:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:13.3:p5:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:13.4:beta3:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:14.0:-:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:14.0:beta5:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:14.0:p1:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:14.0:p2:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:14.0:p3:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:14.0:p4:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:14.0:p5:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:14.0:p6:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:14.0:p7:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:14.0:p8:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:14.0:p9:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:14.0:rc3:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:14.0:rc4-p1:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:14.1:-:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:14.1:p1:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:14.1:p2:*:*:*:*:*:*
- cpe:2.3:o:freebsd:freebsd:14.1:p3:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.