CVE-2025-0373
CVSS 3.1 Score 6 of 10 (medium)
Details
Summary
CVE-2025-0373 is a stack buffer overflow vulnerability affecting the implementation of VOP_VPTOFH() function in the cd9660, tarfs, and ext2fs file systems on 64-bit systems. An NFS server exporting one of these file systems can be made to panic when mounted and accessed by an NFS client, potentially leading to further exploitation, such as bypassing file permission checking or remote kernel code execution. However, demonstrating these advanced attacks has not been reported yet. Notably, release kernels with stack protection enabled can prevent some instances of the overflow, causing a panic instead.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- FreeBSD
Affected Vendors
- FreeBSD Project