VYPR
Medium severity5.3NVD Advisory· Published Aug 12, 2024· Updated Jun 17, 2026

CVE-2024-6759

CVE-2024-6759

Description

When mounting a remote filesystem using NFS, the kernel did not sanitize remotely provided filenames for the path separator character, "/". This allows readdir(3) and related functions to return filesystem entries with names containing additional path components.

The lack of validation described above gives rise to a confused deputy problem. For example, a program copying files from an NFS mount could be tricked into copying from outside the intended source directory, and/or to a location outside the intended destination directory.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

20
  • FreeBSD/FreeBSD19 versions
    cpe:2.3:o:freebsd:freebsd:*:*:*:*:*:*:*:*+ 18 more
    • cpe:2.3:o:freebsd:freebsd:*:*:*:*:*:*:*:*range: <13.0
    • cpe:2.3:o:freebsd:freebsd:13.3:p1:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:13.3:p2:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:13.3:p3:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:13.3:p4:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:14.0:beta5:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:14.0:p1:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:14.0:p2:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:14.0:p3:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:14.0:p4:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:14.0:p5:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:14.0:p6:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:14.0:p7:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:14.0:p8:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:14.0:rc3:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:14.0:rc4-p1:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:14.1:p1:*:*:*:*:*:*
    • cpe:2.3:o:freebsd:freebsd:14.1:p2:*:*:*:*:*:*
    • (no CPE)range: 14.1-RELEASE
  • FreeBSD/nfsclientllm-create

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.